agentcash-onboarding

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx agentcash@latest onboard, which downloads and executes the latest version of the agentcash package from the npm registry at runtime. This creates a dependency on an external, unpinned code source which could be updated with malicious content without notice.
  • [COMMAND_EXECUTION]: The skill relies on the execution of shell commands for its core functionality, including npx agentcash balance, npx agentcash fund, and npx agentcash accounts.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to include a user-provided invite code directly into a shell command: npx agentcash@latest onboard <code>. This creates a command injection vulnerability if a malicious user provides a code containing shell metacharacters.
  • Ingestion points: User-supplied <invite-code> processed in SKILL.md.
  • Boundary markers: None present to separate the code from the command structure.
  • Capability inventory: Execution of shell commands via npx.
  • Sanitization: No validation or escaping is specified for the input code before it is passed to the shell.
  • [EXTERNAL_DOWNLOADS]: The skill prompts the download of external software from the npm registry and provides links to external domains (agentcash.dev) for funding and onboarding steps.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — agentcash-onboarding