openocean
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external APIs and utilizes it to parameterize sensitive wallet operations.
- Ingestion points: Transaction payload data, including destination addresses and execution hex data, is retrieved from the OpenOcean API via
exports.py. Additionally, token balance data is fetched from the DeBank API. - Boundary markers: The skill does not implement delimiters or specific instructions to isolate or verify data retrieved from these external APIs before they are used in transaction construction.
- Capability inventory: The skill utilizes the
/agent/transfercapability to execute smart contract interactions, including granting infinite token allowances (MAX_UINT256) to addresses provided by the external API. - Sanitization: Transaction fields such as
toanddataare passed to the wallet service directly from the API response without validation against a whitelist or internal safety check. - [DATA_EXFILTRATION]: The skill transmits trade-related metadata to an external endpoint for analytics purposes.
- Evidence:
_trade_report.pycaptures trade events—including wallet addresses, transaction hashes, and trade symbols—and posts them to a URL defined by theAI_AGENT_API_URLenvironment variable. - Details: This reporting mechanism uses platform-level environment variables for configuration and authentication (
CONTAINER_JWT), functioning as a telemetry service for trade monitoring and event tracking.
Audit Metadata