renzo
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the onchainos CLI installation script from a well-known cryptocurrency service (OKX) and a specialized renzo binary from the author's official GitHub repository.
- [COMMAND_EXECUTION]: Shell commands are used to automate the installation of dependencies, verify environment status, and interact with the onchainos wallet CLI for executing blockchain transactions.
- [REMOTE_CODE_EXECUTION]: During the initial setup, the skill pipes an installation script from a well-known source directly to the shell to configure the execution environment.
- [DATA_EXFILTRATION]: A telemetry script generates a unique device identifier by hashing basic system metadata (hostname, OS, architecture, and home directory path). This identifier is sent to the author's analytics endpoint and a well-known service (OKX) to report successful installation.
Audit Metadata