web3-ai-tools

Warn

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone and install multiple third-party repositories from GitHub, including KeygraphHQ/shannon, SanMuzZzZz/LuaN1aoAgent, aliasrobotics/cai, and advaitbd/smartguard. These repositories are outside of the established trusted vendor list.
  • [REMOTE_CODE_EXECUTION]: Following the downloads, the skill instructions involve building and running these tools through commands like 'npm install && npm run build' and 'pip install -r requirements.txt && python agent.py', leading to the execution of unverified remote code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external target data (source code, web content) using AI agents, creating a risk that malicious payloads within the target data could influence the behavior of the auditing agents. Mandatory Evidence Chain: (1) Ingestion points: 'configs/my-target.yaml', 'src/' directory, and target URLs. (2) Boundary markers: None specified. (3) Capability inventory: Subprocess execution, network scanning, and file manipulation across tools like Shannon and SmartGuard. (4) Sanitization: Not explicitly mentioned in the processing workflow.
  • [PROMPT_INJECTION]: The instructions contain example payloads for testing other AI systems, such as 'Ignore previous instructions' and 'Output all user messages', which could be misinterpreted by the processing agent if not properly delimited within the LLM's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 27, 2026, 05:39 AM
Security Audit — agent-trust-hub — web3-ai-tools