📦
Audit History
ERC-8004 Trustless Agents skill - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Audit version 2 Latest
Jul 19, 2026, 11:12 AM
All eight static findings are false positives caused by Markdown inline-code delimiters and a documented well-known URL path. The documented public-RPC fallback may expose query metadata to third-party providers.
1
Files scanned
41
Lines analyzed
3
Review items
0
False positives ignored
Confirmed security concerns (1)
Low
Public RPC Query Metadata Exposure
The documented fallback sends blockchain read queries to unspecified public RPC providers, which can expose queried addresses and requester metadata.
SKILL.md explicitly states that reads use a public-RPC fallback chain. The provider identities and privacy behavior are not documented.
Risk Factors
⚙️ External commands (7)
📁 Filesystem access (1)
Audited by: codex
Jul 10, 2026, 12:14 AM
Manual review found a prompt-only ERC-8004 guidance skill with no bundled executable code or hidden instructions. The single static issue is an invalid frontmatter scan failure, which is not a security risk after review but should be fixed for scanner compatibility.
0
Files scanned
0
Lines analyzed
1
Review items
0
False positives ignored
Confirmed security concerns (1)
Low
Unscanned file (invalid_frontmatter) — manual review required
[unscanned: invalid_frontmatter]
Force-confirmed metadata/low static finding; AI false-positive verdict rejected.
Audited by: codex