executing-agw-transactions

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute shell commands via the agw CLI to perform sensitive blockchain operations, including signing transactions, transferring tokens, and writing to smart contracts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data to populate JSON payloads for shell commands in SKILL.md.
  • Ingestion points: Data is incorporated into JSON strings within shell command templates.
  • Boundary markers: The instructions lack explicit boundary markers or requirements for input sanitization to prevent shell command injection.
  • Capability inventory: The skill uses agw tx and agw contract subcommands to mutate state and sign data.
  • Sanitization: There are no instructions for escaping shell metacharacters in user-supplied fields.
  • [DATA_EXPOSURE]: The skill instructions advise using AGW_* environment variables for configuration. In a blockchain context, these environment variables are likely to contain sensitive credentials, such as private keys, which the agent can access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — executing-agw-transactions