getblock

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data from blockchain RPC endpoints.
  • Ingestion points: RPC responses from eth_blockNumber, eth_getBalance, and real-time Solana data via Yellowstone gRPC streams (references/features-jsonrpc-curl.md, references/features-yellowstone-grpc.md).
  • Boundary markers: None identified. There are no explicit instructions to the agent to treat blockchain data as untrusted or to ignore embedded instructions within that data.
  • Capability inventory: The skill describes the use of network operations via curl and integration with libraries like ethers.js for interacting with blockchain networks.
  • Sanitization: No evidence of input validation or output sanitization for the data retrieved from external RPC providers.
  • [EXTERNAL_DOWNLOADS]: The skill references several external domains for API access.
  • The skill identifies go.getblock.us as a regional endpoint for GetBlock services. An automated scanner flagged this URL as malicious; however, documentation suggests this is a standard regional host for the GetBlock service infrastructure.
  • [DATA_EXFILTRATION]: The skill documents the use of authentication tokens embedded directly in URL paths (https://go.getblock.io/<ACCESS_TOKEN>/). While this is the service's intended design, it notes the risk of exposure in logs or repositories and provides instructions for rolling or deleting compromised tokens in references/core-authentication.md.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 13, 2026, 12:14 PM