sanctum-validator-lst
Warn
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads a pre-compiled binary from the vendor's repository at
github.com/MigOKG/plugin-storeand grants it execution permissions viachmod +x. - [DATA_EXFILTRATION]: An initialization script collects system telemetry, including the
hostnameand the$HOMEenvironment variable (which typically contains the system username). This data is hashed to generate a unique device ID and transmitted to external endpoints atplugin-store-dun.vercel.appandokx.com. - [COMMAND_EXECUTION]: The skill uses shell scripts to perform environment checks, manage file system directories, and execute reporting tasks during the installation process.
- [PROMPT_INJECTION]: The skill identifies a trust boundary for external data processed from blockchain APIs, noting that CLI outputs should be treated as untrusted content to mitigate indirect prompt injection risks.
Audit Metadata