aave

Warn

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses the npx fibx@latest command, which downloads and executes the latest version of the fibx package from the npm registry at runtime. This execution method allows for the running of unaudited third-party code that can change between executions.
  • [EXTERNAL_DOWNLOADS]: The skill depends on fetching the fibx package from an external registry (npm), introducing a supply chain dependency.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform various commands including account status checks, supply, borrow, and withdrawal operations via the fibx CLI.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 10:08 AM