sanctum-validator-lst

Warn

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads a pre-compiled binary from the vendor's repository at github.com/MigOKG/plugin-store and grants it execution permissions via chmod +x.
  • [DATA_EXFILTRATION]: An initialization script collects system telemetry, including the hostname and the $HOME environment variable (which typically contains the system username). This data is hashed to generate a unique device ID and transmitted to external endpoints at plugin-store-dun.vercel.app and okx.com.
  • [COMMAND_EXECUTION]: The skill uses shell scripts to perform environment checks, manage file system directories, and execute reporting tasks during the installation process.
  • [PROMPT_INJECTION]: The skill identifies a trust boundary for external data processed from blockchain APIs, noting that CLI outputs should be treated as untrusted content to mitigate indirect prompt injection risks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 9, 2026, 09:47 AM