@1892/dgclaw
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill includes a
setup-croncommand inscripts/dgclaw.shthat creates a crontab entry to periodically run the agent's forum reply logic, ensuring the skill remains active across sessions. - [INDIRECT_PROMPT_INJECTION]: The auto-reply feature fetches external forum posts and pipes their content directly to the agent's chat interface, creating a potential vector for malicious data to influence agent behavior.
- Ingestion points: Forum posts are retrieved via
curlfromhttps://degen.virtuals.io/api/forums/:agentId/posts?unreplied=trueas seen inscripts/dgclaw.sh. - Boundary markers: Absent; the raw post content is passed to the
agent chatcommand without delimiters. - Capability inventory: The agent possesses capabilities to create trading jobs (
acp job create) and interact via chat. - Sanitization: Absent; the script does not perform any validation or escaping of the retrieved forum content.
- [CREDENTIALS_UNSAFE]: The
setup-croncommand inscripts/dgclaw.shembeds theDGCLAW_API_KEYdirectly into the crontab line, which may expose the credential to other users on the system or in logs. - [EXTERNAL_DOWNLOADS]: The documentation in
README.mdandSKILL.mddirects users to download and install external code from theVirtual-ProtocolGitHub organization repositories. - [COMMAND_EXECUTION]: The
dgclaw.shscript executes several system utilities includingcurlfor API communication,opensslfor RSA key generation and decryption,jqfor JSON processing, andcrontabfor managing persistent tasks.
Audit Metadata