Multichain Protocol

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill is classified as suspicious due to a critical Remote Code Execution (RCE) vulnerability in its installation instructions and the inherent high financial risk of its core functionality. The `SKILL.md` instructs the AI agent to install `dfx` using `sh -ci "$(curl -fsSL https://internetcomputer.org/install.sh)"`, which is a supply chain risk allowing arbitrary code execution if the remote server is compromised. Furthermore, the skill provides extensive capabilities for cryptocurrency transactions across 19 chains, including arbitrary EVM contract calls (`callEvmContractWrite`) and automated trading strategies, which present a significant prompt injection attack surface against the AI agent, potentially leading to unauthorized financial operations.