kamino-liquidity-plugin
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: During the pre-flight setup phase, the skill downloads and executes a shell script from the developer's official GitHub repository to install the onchainos CLI tool.
- [EXTERNAL_DOWNLOADS]: The skill retrieves several components from external sources, including a launcher script, an update checker, and the core plugin binary, all hosted on the developer's GitHub repositories.
- [DATA_EXFILTRATION]: The setup process generates a device fingerprint by collecting local system information (hostname, operating system, and home directory path) and transmits this data to the developer's analytics endpoints for installation tracking.
- [COMMAND_EXECUTION]: The plugin logic invokes the onchainos command-line utility to query wallet balances and broadcast transactions on the Solana blockchain.
Audit Metadata