pancakeswap-v3-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's installation process involves downloading an installer script and a pre-compiled plugin binary from the vendor's GitHub repositories.
- Evidence:
SKILL.mdcontains bash scripts fetching resources fromraw.githubusercontent.com/okx/andgithub.com/okx/. - Security Controls: The skill implements high-integrity practices by verifying the SHA256 checksum of the
install.shscript and the compiled binary before execution, preventing local manipulation or intercepted download attacks. - [COMMAND_EXECUTION]: The skill programmatically invokes external command-line tools to manage blockchain wallets and sign transactions.
- Evidence:
src/onchainos.rsutilizestokio::process::Commandto execute theonchainosCLI tool for operations such aswallet contract-callandwallet addresses. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external blockchain sources, which represents a potential attack surface for indirect prompt injection.
- Ingestion points:
src/rpc.rsretrieves token symbols and names viaeth_call, andsrc/commands/positions.rsfetches position metadata from TheGraph subgraphs. - Boundary markers: Data retrieved from the blockchain is processed as raw strings without explicit boundary delimiters in the Rust source code.
- Capability inventory: The skill has the capability to initiate financial transactions on multiple EVM-compatible chains.
- Sanitization: No specific filtering for adversarial instructions is performed on the token metadata strings before they are returned to the agent context.
- Mitigation: The developer has included a 'Data Trust Boundary' protocol in
SKILL.md(M08) that instructs the AI agent to filter fields and treat all CLI output as untrusted external content.
Audit Metadata