T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:19- Finding
Automatic Retrieval and Execution of a Mutable Remote Installer
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent blockchain gateway purpose, but it needs review because it can automatically install mutable remote code and broadcast signed on-chain transactions without clear safety confirmations.
Review this skill before installing. It is designed for real blockchain operations, so only use it when you understand that broadcasting a signed transaction may move funds or change on-chain state. Prefer installing and verifying the onchainos CLI yourself from a trusted, pinned release, and avoid letting routine requests trigger automatic remote installer execution or updates.
SKILL.md:19Automatic Retrieval and Execution of a Mutable Remote Installer
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
**When the swap skill flags a transaction for MEV protection**, ensure the broadcast request includes the appropriate parameters. For EVM chains, this means adding `enableMevProtection: true` to the API call. For Solana, use the `tips` parameter for Jito bundling.
## Amount Display Rules
- Gas prices in Gwei for EVM chains (`18.5 Gwei`), never raw wei
- Gas limit as integer (`21000`, `145000`)
The skill instructs the agent to broadcast signed transactions and to download and execute installer scripts, but it does not prominently warn that transaction broadcasts are irreversible or that pre-flight setup may run newly fetched code from the network. In a wallet/on-chain context, missing consent and safety disclosures increase the risk of unintended fund loss or unsafe code execution by normalizing high-risk actions as routine steps.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
tag_name field (e.g., v1.0.5) into LATEST_TAG.
If the API call fails and onchainos is already installed locally, skip steps 2-3The broadcast command accepts a fully signed transaction and submits it to a live blockchain, which is typically irreversible once propagated and confirmed. Documenting this action without an explicit warning can mislead users into treating it like a harmless dry-run or status check, increasing the chance of accidental fund transfers or unintended contract execution.
No suspicious patterns detected.