blockrun
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of a third-party Python package
blockrun-llmfrom a public registry. This dependency is not from a well-known service or trusted organization. - [COMMAND_EXECUTION]: The skill utilizes
Bashtools to install the required SDK, execute Python scripts for model interaction, and manage wallet session files in the user's home directory. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for user-supplied data to external LLMs, creating a surface for potential prompt injection attacks.
- Ingestion points: User prompts are directly passed to
client.chat()andclient.generate()functions within the Python code examples inSKILL.md. - Boundary markers: The instructions do not define delimiters or warnings to prevent the downstream models from following malicious instructions embedded in the user data.
- Capability inventory: The skill has permissions for file reading, shell command execution (Python/Pip), and network connectivity via the installed SDK.
- Sanitization: There is no evidence of input validation, filtering, or sanitization before external transmission.
Audit Metadata