@1892/dgclaw

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill includes a setup-cron command in scripts/dgclaw.sh that creates a crontab entry to periodically run the agent's forum reply logic, ensuring the skill remains active across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The auto-reply feature fetches external forum posts and pipes their content directly to the agent's chat interface, creating a potential vector for malicious data to influence agent behavior.
  • Ingestion points: Forum posts are retrieved via curl from https://degen.virtuals.io/api/forums/:agentId/posts?unreplied=true as seen in scripts/dgclaw.sh.
  • Boundary markers: Absent; the raw post content is passed to the agent chat command without delimiters.
  • Capability inventory: The agent possesses capabilities to create trading jobs (acp job create) and interact via chat.
  • Sanitization: Absent; the script does not perform any validation or escaping of the retrieved forum content.
  • [CREDENTIALS_UNSAFE]: The setup-cron command in scripts/dgclaw.sh embeds the DGCLAW_API_KEY directly into the crontab line, which may expose the credential to other users on the system or in logs.
  • [EXTERNAL_DOWNLOADS]: The documentation in README.md and SKILL.md directs users to download and install external code from the Virtual-Protocol GitHub organization repositories.
  • [COMMAND_EXECUTION]: The dgclaw.sh script executes several system utilities including curl for API communication, openssl for RSA key generation and decryption, jq for JSON processing, and crontab for managing persistent tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 06:49 PM
Security Audit — agent-trust-hub — @1892/dgclaw