blockrun

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a third-party Python package blockrun-llm from a public registry. This dependency is not from a well-known service or trusted organization.
  • [COMMAND_EXECUTION]: The skill utilizes Bash tools to install the required SDK, execute Python scripts for model interaction, and manage wallet session files in the user's home directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for user-supplied data to external LLMs, creating a surface for potential prompt injection attacks.
  • Ingestion points: User prompts are directly passed to client.chat() and client.generate() functions within the Python code examples in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or warnings to prevent the downstream models from following malicious instructions embedded in the user data.
  • Capability inventory: The skill has permissions for file reading, shell command execution (Python/Pip), and network connectivity via the installed SDK.
  • Sanitization: There is no evidence of input validation, filtering, or sanitization before external transmission.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — blockrun