Private client (not disclosed) — AI and MCP Review

Audit report published Aug 2026. Web3 AI agent platform (LLM planner, MCP tools, RAG, on-chain wallet) · Python (examples).

Findings at a glance

SeverityCount
Critical1
High2
Medium3
Low1
Total7

Summary

Safe Edges assessed an autonomous Web3 AI agent platform for a private client, covering prompt handling, MCP tool registration, retrieval (RAG), wallet permissions, agent-to-agent trust and agent memory. Seven issues were identified: one Critical, two High, three Medium and one Low. The Critical issue was that LLM-generated execution plans were signed and broadcast without checking them against the user's intent, so a prompt injection through chat, Discord, governance proposals or retrieved documents could trigger arbitrary transactions. The original report did not record resolution statuses.

Read the full report (PDF).

Findings

Critical (1)

High (2)

Medium (3)

Low (1)

More published reports

Related services

Get a fixed quote in 24 hours

Send the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.