pendle-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads its binary components and the 'onchainos' CLI tool from official vendor repositories on GitHub (okx/plugin-store and okx/onchainos-skills). All downloads are protected by SHA256 checksum verification to ensure file integrity before execution.
- [COMMAND_EXECUTION]: The skill interacts with the system by executing the 'onchainos' CLI tool to manage wallet sessions and sign transactions. These commands are constructed using parameters that undergo strict validation (e.g., EVM address format and amount checks).
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Pendle Finance APIs and blockchain RPC providers. It includes a specific 'Data Trust Boundary' section instructing the AI agent to treat all external output as untrusted and to filter sensitive fields. Furthermore, the skill's binary implements 'validate_sdk_calldata' to inspect transaction payloads before they are submitted, preventing common token-draining attacks by checking function selectors and contract addresses against a known whitelist.
- [SAFE]: The skill implements a robust 'Live Trading Confirmation Protocol' that requires explicit user confirmation, risk limit checks, and session-bounded autonomy, preventing accidental or autonomous unauthorized trades.
Audit Metadata