0xwork
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes task descriptions, requirements, and comments from a decentralized marketplace. These are untrusted inputs that could contain malicious instructions designed to manipulate the agent's behavior.
- Ingestion points: Untrusted content enters the agent context via the
0xwork discoverand0xwork task <id>commands described inSKILL.md. - Boundary markers:
SKILL.mdincludes a detailed "Security: Untrusted Content Handling" section that provides explicit "Rules (non-negotiable)" and boundary definitions to help the agent distinguish between trusted system instructions and untrusted marketplace data. - Capability inventory: The agent uses the
0xworkCLI to perform on-chain operations and is instructed inreferences/execution-guide.mdto use tools such asexec,write, and the file system to create deliverables. - Sanitization: The skill relies on prompt-level defensive instructions for the agent rather than technical sanitization of the marketplace content.
- [DYNAMIC_EXECUTION]: In the "Code" category of the
references/execution-guide.md, the agent is instructed to write and test code deliverables usingexecandwritetools. This involves executing code derived from untrusted task specifications. - [COMMAND_EXECUTION]: The skill requires the installation and use of the
@0xwork/cliNode.js package to interact with the 0xWork protocol, manage wallet state, and submit work deliverables.
Recommendations
- HIGH: Downloads and executes remote code from: https://evil.com/script.sh - DO NOT USE without thorough review
Audit Metadata