mining-with-bigcoin
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for executing shell commands using the
agwCLI tool to interact with blockchain smart contracts. - Evidence: Multiple examples in
SKILL.mddemonstrate the use ofagw contract writeandagw tx callsto query and submit transactions. - [INDIRECT_PROMPT_INJECTION]: The skill involves reading data from external smart contracts, creating a surface where untrusted data from the blockchain could influence the agent's behavior.
- Ingestion points: The agent is instructed to read values from the Bigcoin Game contract (e.g.,
pendingRewards,ownerToFacility). - Boundary markers: The skill includes recommendations to use the
--dry-runflag, allowing for transaction verification before submission. - Capability inventory: The skill utilizes
agw contract writeandagw tx callsfor write operations and queries. - Sanitization: No explicit instructions for sanitizing or escaping the data read from the blockchain are present.
Audit Metadata