skills/bankrbot/skills/onchainkit/Gen Agent Trust Hub

onchainkit

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes Python scripts (create-onchain-app.py, setup-environment.py, validate-setup.py) that perform development tasks by executing shell commands. These tasks include initializing new projects with NPM, checking for installed dependencies, and running build tests. User-supplied project names are sanitized to prevent shell injection.\n- [EXTERNAL_DOWNLOADS]: The setup and initialization scripts facilitate the download of official packages and development tools from the NPM registry. Specifically, the skill installs the @coinbase/onchainkit library and its required peer dependencies (e.g., viem, wagmi).\n- [REMOTE_CODE_EXECUTION]: The skill uses the npm create onchain@latest command to bootstrap new applications. This pattern involves downloading and executing the latest initialization logic from a remote registry. As this targets the official generator for a well-known service, it is considered a legitimate development workflow.\n- [DYNAMIC_EXECUTION]: The component-generator.py script dynamically generates React component files based on pre-defined templates to assist in rapid application development. This utility assists developers by providing boilerplate code for wallet connections, token swaps, and identity displays.\n- [INDIRECT_PROMPT_INJECTION]: The skill generates UI components that process untrusted data from blockchain sources (e.g., ENS names, token metadata) and user inputs (e.g., search queries). This represents a potential surface for indirect prompt injection if the external data is maliciously crafted.\n
  • Ingestion points: The Identity, Avatar, and TokenSearch components ingest data from blockchain records and user-provided strings.\n
  • Boundary markers: The generated code templates do not include explicit delimiters or 'ignore' instructions for the processed external data.\n
  • Capability inventory: The skill scripts can execute shell commands for project management, and the generated components perform network operations to interact with blockchain RPC providers.\n
  • Sanitization: The skill relies on the built-in data handling and security protocols of the official @coinbase/onchainkit library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — onchainkit