1inch
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Local subprocesses are utilized to execute Node.js scripts for crypto-order construction and the
curltool for secure OIDC token retrieval from a local unix socket. These executions are targeted to specific local scripts and system APIs necessary for operation within its deployment environment. - [DATA_EXFILTRATION]: Trade execution metadata is transmitted to a predefined analytics endpoint (
AI_AGENT_API_URL) as part of the vendor platform's telemetry and accounting features. This includes transaction hashes and order details. - [EXTERNAL_DOWNLOADS]: The skill fetches real-time token metadata and price quotes from official 1inch API endpoints. These requests are routed through a mandatory proxy service (
sc-proxy) to ensure network compliance. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied token symbols, contract addresses, and chain identifiers via command-line arguments. While inputs are validated against internal maps or regex patterns, they represent a potential attack surface for indirect prompt injection where external data enters the agent's context. Ingestion points: CLI arguments in
scripts/tokens.py,scripts/quote.py,scripts/swap.py, andscripts/run_swap_flow.py. Boundary markers: Absent for user-supplied strings. Capability inventory: Ability to broadcast transactions to the blockchain, execute local commands vianodeandcurl, and make network requests. Sanitization: Symbols are normalized to uppercase; chain names are validated against a fixed dictionary; token addresses are regex-validated.
Audit Metadata