mining-with-bigcoin

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for executing shell commands using the agw CLI tool to interact with blockchain smart contracts.
  • Evidence: Multiple examples in SKILL.md demonstrate the use of agw contract write and agw tx calls to query and submit transactions.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading data from external smart contracts, creating a surface where untrusted data from the blockchain could influence the agent's behavior.
  • Ingestion points: The agent is instructed to read values from the Bigcoin Game contract (e.g., pendingRewards, ownerToFacility).
  • Boundary markers: The skill includes recommendations to use the --dry-run flag, allowing for transaction verification before submission.
  • Capability inventory: The skill utilizes agw contract write and agw tx calls for write operations and queries.
  • Sanitization: No explicit instructions for sanitizing or escaping the data read from the blockchain are present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — mining-with-bigcoin