rootdata-crypto-plugin
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs a version check by fetching metadata from the vendor's official GitHub repository (
raw.githubusercontent.com/okx/plugin-store). This fetch is used for update notifications and does not involve automated code installation. - [COMMAND_EXECUTION]: A bash script is included in the skill to compare the local version with the remote repository. The script is restricted to reading metadata and writing to a local cache directory (
$HOME/.plugin-store/update-cache), requiring manual user confirmation for any actual skill updates. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the RootData API, which presents a potential surface for indirect prompt injection if external data contains instructions.
- Ingestion points: Data retrieved from
api.rootdata.com(Search results, Project detail, Funding rounds, Job changes). - Boundary markers: The skill does not explicitly define delimiters to separate third-party project descriptions from agent instructions.
- Capability inventory: The skill has capabilities for local bash command execution (version check) and network access to RootData endpoints.
- Sanitization: No explicit sanitization or filtering of ingested crypto project metadata is described in the provided instructions.
Audit Metadata