emblem-defi-yield

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/yield-scan.sh is vulnerable to shell command injection. It accepts a CHAIN argument and interpolates it directly into a shell command string without any sanitization. A malicious input containing shell metacharacters (e.g., ; or &) would allow arbitrary command execution on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill requires the @emblemvault/agentwallet global NPM package. This is a vendor-owned utility provided via the public NPM registry for the skill's core functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external blockchain APIs and DeFi aggregators (such as Birdeye and Nansen). This represents a vulnerability surface where manipulated token metadata or protocol descriptions from these untrusted sources could be used to influence the AI agent's logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 03:36 PM
Security Audit — agent-trust-hub — emblem-defi-yield