Bread Protocal
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is designed to enable an AI agent to interact with the Bread Protocol dApp on the Base blockchain, facilitating actions like proposing tokens, backing proposals, and claiming rewards/refunds. All instructions and code examples provided in SKILL.md, references/contracts.md, and references/workflows.md are directly related to this stated purpose, involving standard web3 interactions with specified smart contract addresses (e.g., 0xAfcAF9e3c9360412cbAa8475ed85453170E75fD5 for BREAD token, 0xE7Ce600e0d1aB2b453aDdd6E72bB87c652f34E33 for Bakery). There is no evidence of intentional harmful behavior such as data exfiltration, malicious execution, persistence mechanisms, or prompt injection attempts against the agent to deviate from its intended function. The mention of `privateKeyToAccount('0x...')` in code examples is illustrative for wallet setup, not an instruction for the agent to expose or use a hardcoded private key.
