skills/bankrbot/skills/0xwork/Gen Agent Trust Hub

0xwork

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes task descriptions, requirements, and comments from a decentralized marketplace. These are untrusted inputs that could contain malicious instructions designed to manipulate the agent's behavior.
  • Ingestion points: Untrusted content enters the agent context via the 0xwork discover and 0xwork task <id> commands described in SKILL.md.
  • Boundary markers: SKILL.md includes a detailed "Security: Untrusted Content Handling" section that provides explicit "Rules (non-negotiable)" and boundary definitions to help the agent distinguish between trusted system instructions and untrusted marketplace data.
  • Capability inventory: The agent uses the 0xwork CLI to perform on-chain operations and is instructed in references/execution-guide.md to use tools such as exec, write, and the file system to create deliverables.
  • Sanitization: The skill relies on prompt-level defensive instructions for the agent rather than technical sanitization of the marketplace content.
  • [DYNAMIC_EXECUTION]: In the "Code" category of the references/execution-guide.md, the agent is instructed to write and test code deliverables using exec and write tools. This involves executing code derived from untrusted task specifications.
  • [COMMAND_EXECUTION]: The skill requires the installation and use of the @0xwork/cli Node.js package to interact with the 0xWork protocol, manage wallet state, and submit work deliverables.
Recommendations
  • HIGH: Downloads and executes remote code from: https://evil.com/script.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — 0xwork