ion-protocol

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads platform-specific binaries for the ion-protocol CLI directly from the vendor's official GitHub repository.- [REMOTE_CODE_EXECUTION]: An environment setup script from OKX's public repository is executed using a shell pipe during the initial setup phase.- [COMMAND_EXECUTION]: Local system utilities such as hostname, uname, and shasum are used to generate an installation identifier and configure the plugin environment.- [DATA_EXFILTRATION]: Anonymous installation metadata including plugin versioning and a system-derived identifier is sent to the vendor's statistics endpoint on Vercel and the OKX API for telemetry purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 09:46 AM