blockrun

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the blockrun-llm Python package, which originates from an unverified external source.\n- [COMMAND_EXECUTION]: The skill utilizes Bash permissions to install packages, execute Python scripts, and source environment files, providing a broad surface for command execution.\n- [DATA_EXFILTRATION]: User prompts, interaction history, and sensitive context are transmitted to the third-party BlockRun proxy service. The SDK also handles crypto wallet transactions, establishing a pathway for financial data exfiltration if the service is compromised.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) and contains deceptive metadata.\n
  • Ingestion points: The agent ingests untrusted content from external model outputs and real-time search results from X/Twitter.\n
  • Boundary markers: No delimiters or isolation instructions are provided to help the agent distinguish its own instructions from external data.\n
  • Capability inventory: The agent possesses Bash access and the ability to autonomously spend funds from a crypto wallet.\n
  • Sanitization: There is no evidence of input validation or output sanitization for the data retrieved from external LLMs or social media feeds.\n
  • Deception: The skill description claims access to non-existent models such as 'GPT-5.2' and 'Grok-3'. This misleading information is a pattern often associated with scams or credential harvesting.\n- [CREDENTIALS_UNSAFE]: The skill manages a sensitive session and wallet file located at $HOME/.blockrun/.session. The presence of a local wallet file combined with network access creates a risk of credential exposure or theft.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — blockrun