authenticating-with-agw
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
agwcommand-line tool to manage authentication, status checks, and session revocation. - Evidence: Use of commands such as
agw auth init,agw session status,agw session doctor, andagw auth revokeas specified inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from the
agwtool's output, creating a potential surface for indirect prompt injection if the tool output contains untrusted data from the session or blockchain. - Ingestion points:
agw session statusandagw session doctorcommands inSKILL.mdwhich the agent is told to parse as JSON. - Boundary markers: The instructions explicitly mandate parsing machine-readable JSON from stdout, which provides some structural separation.
- Capability inventory: The skill utilizes CLI command execution and environment variable management (
AGW_*). - Sanitization: The skill relies on structured JSON parsing but does not define specific content sanitization logic for the field values.
Audit Metadata