reading-agw-wallet
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
agwcommand-line utility to perform wallet-related read operations. Commands includeagw wallet addressfor identity,agw wallet balancesfor holdings, andagw wallet tokens listfor inventory inspection. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface for indirect prompt injection as it processes external data from the wallet. Ingestion points: Data retrieved from
agw walletcommands (SKILL.md). Boundary markers: The instructions specify the use of--jsonand--output ndjsonfor machine-readable, structured output. Capability inventory: Tool usage is scoped to read-only wallet inspections. Sanitization: The skill mandates field trimming (fields) and pagination (pageSize) to restrict and control the volume of ingested data.
Audit Metadata