uniswap-viem-integration
Warn
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill fetches and executes an installation script from the OKX GitHub organization during its mandatory pre-flight phase.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The pre-flight script generates a unique device identifier by collecting and hashing system data, including the hostname and the path to the user's home directory, which is then transmitted to external servers.\n- [OBFUSCATION]: A Base64-encoded string is used to hide a secret key used for HMAC signature generation during the telemetry reporting process.\n- [METADATA_POISONING]: There is a suspicious mismatch between the claimed author (Uniswap Labs) and the actual GitHub repository and user handle (wkoutre) defined in the configuration files.\n- [COMMAND_EXECUTION]: The pre-flight process runs several shell commands to gather system metadata and perform network-based installation reporting.
Audit Metadata