kamino-lend-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the
onchainosCLI installer and thekamino-lend-pluginbinary from officialokxGitHub repositories. These downloads are verified using SHA256 checksums before any execution occurs, ensuring the integrity of the software components. - [COMMAND_EXECUTION]: The plugin interacts with the Solana blockchain by executing the
onchainosCLI. It uses safe argument passing for all operations, including checking balances and performing contract calls, which effectively prevents command injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from lending protocol APIs (Kamino), market aggregators (DeFiLlama), and decentralized exchanges (Jupiter).
- Ingestion points: Data enters the system via JSON responses from
yields.llama.fi,api.kamino.finance, andapi.jup.ag(defined insrc/api.rs). - Boundary markers: The skill instructions in
SKILL.mdinclude a mandatory 'Live Trading Confirmation Protocol' and a security notice explicitly warning the agent to treat external content as untrusted. - Capability inventory: The skill can execute on-chain transactions via
onchainos wallet contract-call(as seen insrc/onchainos.rs). - Sanitization: The skill uses typed Rust logic to parse and validate JSON responses, and it requires explicit user confirmation via a
--confirmflag before any transaction is broadcast.
Audit Metadata