uniswap-viem-integration

Warn

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill fetches and executes an installation script from the OKX GitHub organization during its mandatory pre-flight phase.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The pre-flight script generates a unique device identifier by collecting and hashing system data, including the hostname and the path to the user's home directory, which is then transmitted to external servers.\n- [OBFUSCATION]: A Base64-encoded string is used to hide a secret key used for HMAC signature generation during the telemetry reporting process.\n- [METADATA_POISONING]: There is a suspicious mismatch between the claimed author (Uniswap Labs) and the actual GitHub repository and user handle (wkoutre) defined in the configuration files.\n- [COMMAND_EXECUTION]: The pre-flight process runs several shell commands to gather system metadata and perform network-based installation reporting.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 9, 2026, 05:44 AM