tron-java
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for cloning the official TRON Protocol repository (
https://github.com/tronprotocol/java-tron.git) and using JitPack (https://jitpack.io) for dependencies. These are standard practices for this project and involve recognized developer resources. - [COMMAND_EXECUTION]: Documentation includes standard build and execution commands such as
./gradlew buildandjava -jar FullNode.jar. It also describes the use of astart.shutility script for managing the node lifecycle, including automated builds and release downloads from the project's GitHub repository. - [REMOTE_CODE_EXECUTION]: The skill documents the use of official scripts like
install_dependencies.shandstart.sh --release, which involve downloading and executing code or binaries from the TRON Protocol GitHub organization. These are standard maintenance procedures for the software. - [CREDENTIALS_UNSAFE]: Instructions are provided for configuring Super Representative (SR) nodes, which involves providing a private key via the
localwitnessconfiguration field or CLI arguments. The documentation includes appropriate security warnings to keep the configuration file secure and mentions keystore alternatives. - [SAFE]: No malicious patterns, obfuscation, or unauthorized data access attempts were detected. The content represents legitimate technical documentation for blockchain infrastructure.
Audit Metadata