authenticating-with-agw

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the agw command-line tool to manage authentication, status checks, and session revocation.
  • Evidence: Use of commands such as agw auth init, agw session status, agw session doctor, and agw auth revoke as specified in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from the agw tool's output, creating a potential surface for indirect prompt injection if the tool output contains untrusted data from the session or blockchain.
  • Ingestion points: agw session status and agw session doctor commands in SKILL.md which the agent is told to parse as JSON.
  • Boundary markers: The instructions explicitly mandate parsing machine-readable JSON from stdout, which provides some structural separation.
  • Capability inventory: The skill utilizes CLI command execution and environment variable management (AGW_*).
  • Sanitization: The skill relies on structured JSON parsing but does not define specific content sanitization logic for the field values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — authenticating-with-agw