chainbase-openapi-skill
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches an OpenAPI schema from the author's GitHub repository (holon-run) to configure the CLI tool mapping. This is a vendor-owned resource for legitimate configuration.\n- [COMMAND_EXECUTION]: Uses the uxc tool to perform read-only operations on indexed blockchain data. All operations are limited to data retrieval.\n- [CREDENTIALS_UNSAFE]: Recommends using environment variables (CHAINBASE_API_KEY) and the uxc credential manager, avoiding hardcoded secrets.\n- [PROMPT_INJECTION]: The skill processes untrusted blockchain data through CLI arguments. Ingestion points: address and tx_hash query parameters. Boundary markers: none. Capability inventory: restricted to read-only network calls. Sanitization: managed by the uxc execution environment.
Audit Metadata