blockrun

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the blockrun-llm Python package via pip. This is a third-party dependency from an unverified source.\n- [DATA_EXFILTRATION]: User queries and data are sent to an external service ('BlockRun') that acts as a proxy for other LLM providers, exposing sensitive information to a third-party intermediary.\n- [CREDENTIALS_UNSAFE]: The skill manages sensitive wallet and session information in a local file at $HOME/.blockrun/.session and provides methods for the agent to access and display these sensitive details.\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the ingestion of real-time, untrusted data from X/Twitter and the web using the search=True parameter.\n
  • Ingestion points: Untrusted data is fetched through the Grok Live Search feature documented in SKILL.md.\n
  • Boundary markers: There are no instructions or delimiters provided to help the agent distinguish between external data and system instructions.\n
  • Capability inventory: The skill has Bash(python:*) permissions, allowing the execution of code that may be influenced by untrusted external data.\n
  • Sanitization: The skill does not implement any sanitization or validation for the fetched content.\n- [METADATA_POISONING]: The documentation references non-existent or futuristic AI models and specific pricing, which could be deceptive regarding the actual services being used.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — blockrun