gate-exchange-assets
Warn
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads
gate-clibinaries and checksum files from the official Gate repository on GitHub (github.com/gate/gate-cli/releases). These downloads are performed during the setup process triggered bySKILL.mdand thesetup.shscript. - [PRIVILEGE_ESCALATION]: The
setup.shinstallation script contains logic to usesudo installif the primary user-local installation path (~/.openclaw/skills/bin) is not writable, allowing the skill to write to protected system directories like/usr/local/bin. - [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution to invoke various subcommands of the
gate-clitool (e.g.,cex wallet balance total,cex spot account get) to retrieve financial data. - [DYNAMIC_EXECUTION]: The skill resolves the binary path for
gate-cliat runtime using a prioritized search order across multiple directories, including system paths and user-local directories. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided input, such as currency codes, and interpolates them directly into shell command arguments without explicit sanitization or escaping mechanisms.
- Ingestion points: User-supplied currency names in queries (e.g., "How many {COIN} do I have?") handled in
SKILL.mdandscenarios.md. - Boundary markers: The skill specifies routing logic and read-only command mappings but lacks explicit delimiters or instructions to ignore embedded control characters in the user-supplied data.
- Capability inventory: The agent has the ability to execute subprocesses through the
gate-clicommand-line utility. - Sanitization: No validation, regex filtering, or shell escaping is described for the interpolated
{COIN}variable.
Audit Metadata