emblem-defi-yield
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/yield-scan.shis vulnerable to shell command injection. It accepts aCHAINargument and interpolates it directly into a shell command string without any sanitization. A malicious input containing shell metacharacters (e.g.,;or&) would allow arbitrary command execution on the host system. - [EXTERNAL_DOWNLOADS]: The skill requires the
@emblemvault/agentwalletglobal NPM package. This is a vendor-owned utility provided via the public NPM registry for the skill's core functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external blockchain APIs and DeFi aggregators (such as Birdeye and Nansen). This represents a vulnerability surface where manipulated token metadata or protocol descriptions from these untrusted sources could be used to influence the AI agent's logic.
Audit Metadata