agentcash-onboarding
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill utilizes
npx agentcash@latest onboard, which downloads and executes the latest version of theagentcashpackage from the npm registry at runtime. This creates a dependency on an external, unpinned code source which could be updated with malicious content without notice. - [COMMAND_EXECUTION]: The skill relies on the execution of shell commands for its core functionality, including
npx agentcash balance,npx agentcash fund, andnpx agentcash accounts. - [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to include a user-provided invite code directly into a shell command:
npx agentcash@latest onboard <code>. This creates a command injection vulnerability if a malicious user provides a code containing shell metacharacters. - Ingestion points: User-supplied
<invite-code>processed inSKILL.md. - Boundary markers: None present to separate the code from the command structure.
- Capability inventory: Execution of shell commands via
npx. - Sanitization: No validation or escaping is specified for the input code before it is passed to the shell.
- [EXTERNAL_DOWNLOADS]: The skill prompts the download of external software from the npm registry and provides links to external domains (agentcash.dev) for funding and onboarding steps.
Audit Metadata