bnbagent

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the twak (Trust Wallet Agent Kit) CLI to manage wallet operations and broadcast transactions without exposing private keys directly to the SDK runtime.
  • Evidence: examples/twak/quickstart.py and bnbagent/wallets/twak_provider.py use subprocess.run to call the twak binary for wallet creation, signing, and intent execution.
  • [DATA_EXFILTRATION]: The skill manages sensitive file paths for storing encrypted keystores and wallet state, which is a standard requirement for on-chain agents.
  • Evidence: The SDK accesses ~/.bnbagent/wallets/ for Keystore V3 files and ~/.twak/wallet.json for mnemonic-based custody, as documented in references/wallets.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from blockchain job descriptions and external news sources, presenting a potential surface for indirect injection attacks.
  • Evidence Chain:
  • Ingestion points: examples/agent-server/src/service.py ingests job descriptions and DuckDuckGo news results.
  • Boundary markers: Uses structured JobDescription parsing and requires cryptographic hashes for deliverables.
  • Capability inventory: The agent has the ability to sign blockchain transactions and perform network writes to IPFS gateways.
  • Sanitization: Employs a SigningPolicy that explicitly denylists dangerous EIP-712 types (like Permit) and restricts signing to specific EIP-3009 transfer types.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known and protocol-relevant services to perform news searches and interact with decentralized storage.
  • Evidence: Communicates with DuckDuckGo (news), Pinata (IPFS), and standard BNB Chain RPC endpoints for core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — bnbagent