chainbase-openapi-skill

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches an OpenAPI schema from the author's GitHub repository (holon-run) to configure the CLI tool mapping. This is a vendor-owned resource for legitimate configuration.\n- [COMMAND_EXECUTION]: Uses the uxc tool to perform read-only operations on indexed blockchain data. All operations are limited to data retrieval.\n- [CREDENTIALS_UNSAFE]: Recommends using environment variables (CHAINBASE_API_KEY) and the uxc credential manager, avoiding hardcoded secrets.\n- [PROMPT_INJECTION]: The skill processes untrusted blockchain data through CLI arguments. Ingestion points: address and tx_hash query parameters. Boundary markers: none. Capability inventory: restricted to read-only network calls. Sanitization: managed by the uxc execution environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 03:14 AM
Security Audit — agent-trust-hub — chainbase-openapi-skill