bnbagent
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the
twak(Trust Wallet Agent Kit) CLI to manage wallet operations and broadcast transactions without exposing private keys directly to the SDK runtime. - Evidence:
examples/twak/quickstart.pyandbnbagent/wallets/twak_provider.pyusesubprocess.runto call thetwakbinary for wallet creation, signing, and intent execution. - [DATA_EXFILTRATION]: The skill manages sensitive file paths for storing encrypted keystores and wallet state, which is a standard requirement for on-chain agents.
- Evidence: The SDK accesses
~/.bnbagent/wallets/for Keystore V3 files and~/.twak/wallet.jsonfor mnemonic-based custody, as documented inreferences/wallets.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from blockchain job descriptions and external news sources, presenting a potential surface for indirect injection attacks.
- Evidence Chain:
- Ingestion points:
examples/agent-server/src/service.pyingests job descriptions and DuckDuckGo news results. - Boundary markers: Uses structured
JobDescriptionparsing and requires cryptographic hashes for deliverables. - Capability inventory: The agent has the ability to sign blockchain transactions and perform network writes to IPFS gateways.
- Sanitization: Employs a
SigningPolicythat explicitly denylists dangerous EIP-712 types (like Permit) and restricts signing to specific EIP-3009 transfer types. - [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known and protocol-relevant services to perform news searches and interact with decentralized storage.
- Evidence: Communicates with DuckDuckGo (news), Pinata (IPFS), and standard BNB Chain RPC endpoints for core functionality.
Audit Metadata