clanker-plugin

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data such as token names, symbols, and price metadata from the Clanker API and on-chain sources (list-tokens, search-tokens, token-info). This content is interpolated into the agent's context, creating a potential surface for indirect prompt injection. The skill includes a 'Data Trust Boundary' notice instructing the agent to treat this data as untrusted and performs a security scan via onchainos security token-scan before executing reward claims.
  • [EXTERNAL_DOWNLOADS]: The skill's pre-flight scripts download an installation script and a compiled binary from the vendor's official GitHub repositories (okx/onchainos-skills and okx/plugin-store). These downloads are verified against SHA256 checksums provided by the vendor before execution.
  • [COMMAND_EXECUTION]: The skill executes shell commands to facilitate token deployment and rewards management. It leverages the onchainos CLI for wallet operations and npx skills add for dependency management. A mandatory 'Live Trading Confirmation Protocol' ensures that no on-chain transactions are broadcast without explicit user confirmation and parameter preview.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:49 PM