Caveat verdict
guardrail-smart-accounts
ERC-4337 smart account spending limits for AI agents using transparent, user-controlled policy enforcement at the contract level with clearly declared env vars.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (4)
Possible hardcoded credential
SKILL.md ยท code ยท token: "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48
Accesses process.env โ reads environment variables
SKILL.md ยท code
Accesses sensitive environment variables
SKILL.md ยท code ยท process.env.GUARDRAIL_DASHBOARD_API_KEY
fetch() โ outbound network request
SKILL.md ยท code
Permissions & capabilities
Requires 3 environment variables.
network_outcredential_accessdata_encoding Is this flag fair?
Thanks โ recorded.