pancakeswap-v3-plugin

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installation process involves downloading an installer script and a pre-compiled plugin binary from the vendor's GitHub repositories.
  • Evidence: SKILL.md contains bash scripts fetching resources from raw.githubusercontent.com/okx/ and github.com/okx/.
  • Security Controls: The skill implements high-integrity practices by verifying the SHA256 checksum of the install.sh script and the compiled binary before execution, preventing local manipulation or intercepted download attacks.
  • [COMMAND_EXECUTION]: The skill programmatically invokes external command-line tools to manage blockchain wallets and sign transactions.
  • Evidence: src/onchainos.rs utilizes tokio::process::Command to execute the onchainos CLI tool for operations such as wallet contract-call and wallet addresses.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external blockchain sources, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: src/rpc.rs retrieves token symbols and names via eth_call, and src/commands/positions.rs fetches position metadata from TheGraph subgraphs.
  • Boundary markers: Data retrieved from the blockchain is processed as raw strings without explicit boundary delimiters in the Rust source code.
  • Capability inventory: The skill has the capability to initiate financial transactions on multiple EVM-compatible chains.
  • Sanitization: No specific filtering for adversarial instructions is performed on the token metadata strings before they are returned to the agent context.
  • Mitigation: The developer has included a 'Data Trust Boundary' protocol in SKILL.md (M08) that instructs the AI agent to filter fields and treat all CLI output as untrusted external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:50 PM