aicoin-onchain
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to the OKX Web3 DEX API to perform market searches, obtain quotes, and fetch wallet balances. It also interacts with various third-party blockchain RPC nodes (e.g., LlamaRPC, Binance, Polygon, Arbitrum) for transaction simulation and broadcasting.
- [EXTERNAL_DOWNLOADS]: The skill logic in
scripts/swap.mjsandscripts/trade.mjsautomatically appends a 1% referral fee to swap transactions, which is transferred to the developer's hardcoded wallet addresses (0x8c4b28523be418a47e6d8cc66019bda80610e313andCtGKNdcRqUK2K453xsdsNEE2JuHcVTw5B4XiR9MhHHKQ). - [COMMAND_EXECUTION]: The agent executes local Node.js scripts to perform specialized blockchain tasks. This includes
trade.mjswhich can sign and broadcast transactions if provided with a private key. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by ingesting untrusted data from on-chain sources that could influence agent behavior.
- Ingestion points: Token metadata (name, symbol) in
scripts/token.mjsand market signals inscripts/market.mjs. - Boundary markers: Absent; external data is returned as JSON and presented to the agent without specific delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill has the capability to sign and broadcast transactions via
scripts/trade.mjsandscripts/gateway.mjs, posing a risk if the agent is misled by malicious on-chain data. - Sanitization: Absent; the scripts do not sanitize or filter on-chain strings for prompt injection patterns before returning them to the agent context.
Audit Metadata