executing-agw-transactions
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to execute shell commands via the agw CLI to perform sensitive blockchain operations, including signing transactions, transferring tokens, and writing to smart contracts.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data to populate JSON payloads for shell commands in SKILL.md.
- Ingestion points: Data is incorporated into JSON strings within shell command templates.
- Boundary markers: The instructions lack explicit boundary markers or requirements for input sanitization to prevent shell command injection.
- Capability inventory: The skill uses agw tx and agw contract subcommands to mutate state and sign data.
- Sanitization: There are no instructions for escaping shell metacharacters in user-supplied fields.
- [DATA_EXPOSURE]: The skill instructions advise using AGW_* environment variables for configuration. In a blockchain context, these environment variables are likely to contain sensitive credentials, such as private keys, which the agent can access.
Audit Metadata