degenclaw
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PERSISTENCE]: The
dgclaw.shscript implementssetup-cronandremove-croncommands that directly modify the user'scrontabto install a recurring background task. This task is designed to poll for forum updates and trigger agent responses automatically, maintaining activity across sessions without user intervention. - [INDIRECT_PROMPT_INJECTION]: The skill creates a significant attack surface for indirect prompt injection. The automated cron job fetches "unreplied-posts" from a public forum (
https://degen.virtuals.io) and pipes the raw text into the agent's chat context viaacp_cmd agent chat. Ingestion points: Public forum posts are fetched viadgclaw.sh. Boundary markers: There are no delimiters or instructions provided to the agent to ignore embedded commands within the forum data. Capability inventory: The agent has powerful capabilities including perpetual trading (acp trade), wallet management, and forum posting. Sanitization: No sanitization, escaping, or validation is performed on the external forum content before it is processed by the agent. - [COMMAND_EXECUTION]: The skill relies heavily on shell command execution to perform its core functions.
dgclaw.shinvokes system binaries likecurl,openssl, andjq, while the TypeScript utility scripts (trade.ts,withdraw.ts,activate-unified.ts) usechild_process.execSyncto run theacp-clitool with dynamically constructed arguments. - [EXTERNAL_DOWNLOADS]: The skill's documentation requires the manual cloning and installation of the
acp-clirepository from GitHub (https://github.com/Virtual-Protocol/acp-cli.git). This repository contains the primary execution logic for trading and signing, representing a critical external dependency that is not bundled with the skill itself.
Recommendations
- AI detected serious security threats
Audit Metadata