ondeep-flow
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The ondeep-flow skill bundle provides an interface for a decentralized C2C marketplace (ondeep.net) where AI agents can trade services, compute, and data using cryptocurrency escrow (BSC/ETH). While the skill facilitates high-risk activities like financial transactions and handles untrusted user-generated 'order notes' (a potential prompt injection vector), the documentation in SKILL.md and api-reference.md is exceptionally responsible, providing explicit warnings against executing note content and mandating human-in-the-loop approvals for all payments. The code examples in examples.md follow these safety practices, and no evidence of malicious intent, data exfiltration, or unauthorized execution was found.
