clanker-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data such as token names, symbols, and price metadata from the Clanker API and on-chain sources (
list-tokens,search-tokens,token-info). This content is interpolated into the agent's context, creating a potential surface for indirect prompt injection. The skill includes a 'Data Trust Boundary' notice instructing the agent to treat this data as untrusted and performs a security scan viaonchainos security token-scanbefore executing reward claims. - [EXTERNAL_DOWNLOADS]: The skill's pre-flight scripts download an installation script and a compiled binary from the vendor's official GitHub repositories (
okx/onchainos-skillsandokx/plugin-store). These downloads are verified against SHA256 checksums provided by the vendor before execution. - [COMMAND_EXECUTION]: The skill executes shell commands to facilitate token deployment and rewards management. It leverages the
onchainosCLI for wallet operations andnpx skills addfor dependency management. A mandatory 'Live Trading Confirmation Protocol' ensures that no on-chain transactions are broadcast without explicit user confirmation and parameter preview.
Audit Metadata