one-click-token-launch
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
onchainosCLI binary to perform blockchain operations such as checking wallet balances, status, and broadcasting transactions. These calls are implemented usingsubprocess.runwith list-based arguments, which is a security best practice that prevents shell injection vulnerabilities. - [EXTERNAL_DOWNLOADS]: The skill interacts with several external blockchain-related APIs (including PumpPortal, Bags.fm, Moonit, and LetsBonk) to prepare transactions and fetch token metadata. It also facilitates image and metadata uploads to IPFS via pump.fun and Pinata. These external interactions are essential for the skill's core functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses and blockchain logs to display information to the user. This represents a potential surface for indirect prompt injection. However, the risk is effectively mitigated by the 'Live Trading Confirmation Protocol' defined in
SKILL.md, which mandates that the agent must obtain explicit, typed confirmation from the user before executing any real on-chain write operations.
Audit Metadata