blockrun
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
blockrun-llmPython package viapip. This is a third-party dependency from an unverified source.\n- [DATA_EXFILTRATION]: User queries and data are sent to an external service ('BlockRun') that acts as a proxy for other LLM providers, exposing sensitive information to a third-party intermediary.\n- [CREDENTIALS_UNSAFE]: The skill manages sensitive wallet and session information in a local file at$HOME/.blockrun/.sessionand provides methods for the agent to access and display these sensitive details.\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the ingestion of real-time, untrusted data from X/Twitter and the web using thesearch=Trueparameter.\n - Ingestion points: Untrusted data is fetched through the Grok Live Search feature documented in
SKILL.md.\n - Boundary markers: There are no instructions or delimiters provided to help the agent distinguish between external data and system instructions.\n
- Capability inventory: The skill has
Bash(python:*)permissions, allowing the execution of code that may be influenced by untrusted external data.\n - Sanitization: The skill does not implement any sanitization or validation for the fetched content.\n- [METADATA_POISONING]: The documentation references non-existent or futuristic AI models and specific pricing, which could be deceptive regarding the actual services being used.
Audit Metadata