Audit report published Aug 2026. Web3 AI agent platform (LLM planner, MCP tools, RAG, on-chain wallet) · Python (examples).
| Severity | Count |
|---|---|
| Critical | 1 |
| High | 2 |
| Medium | 3 |
| Low | 1 |
| Total | 7 |
Safe Edges assessed an autonomous Web3 AI agent platform for a private client, covering prompt handling, MCP tool registration, retrieval (RAG), wallet permissions, agent-to-agent trust and agent memory. Seven issues were identified: one Critical, two High, three Medium and one Low. The Critical issue was that LLM-generated execution plans were signed and broadcast without checking them against the user's intent, so a prompt injection through chat, Discord, governance proposals or retrieved documents could trigger arbitrary transactions. The original report did not record resolution statuses.
C-01 Prompt Injection Enables Unauthorized On-Chain Transaction ExecutionH-01 Arbitrary Smart Contract Interaction via Tool Argument InjectionH-02 MCP Tool Registration Allows Malicious Blockchain ToolsM-01 RAG Poisoning Influences Autonomous Trading DecisionsM-02 Excessive Wallet Permissions Increase Blast RadiusM-03 Cross-Agent Trust Boundary Allows Strategy ManipulationL-01 Sensitive Wallet Metadata Persisted in Long-Term Agent MemorySend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.