⚠ Medium — Risky tool Analyzed 2026-10-02 · UTC
A security-hygiene observation, not a malware finding. This advisory documents dangerous security practices in a legitimate-purpose tool — for example transmitting credentials over plaintext HTTP, heavy code obfuscation, or automatic global installs. It is not a claim of theft, backdoor or malicious intent: the tool does what it advertises, and the risk falls on its own users and their data. It is published so operators can make an informed decision before installing or deploying it.
Advisory · CLR-2026-3065

@agentgates/cli — autonomous crypto/password agent that injects itself into your agent config

A real tool with high-risk design: autonomous fund movement + site login with no human, and a silent postinstall that writes into CLAUDE.md / .cursor / .windsurf.

Risky toolMediumnpm
What it is

@agentgates/cli is a genuine product (agentgates.ai, repo Carlos-Sotop/agentgates-ai-cli): an AI-agent CLI for crypto/DeFi actions (earn supply|withdraw, swaps, batch --legs-json "several money moves, one approval") and a password manager where "the agent mints its own key and runs the lane itself over signed HTTP" — i.e. it can log into sites autonomously, with no human, via a cloud VM (CVM). Network traffic is first-party (agentgates.ai) plus cryptography-spec references; we found no hidden exfiltration and no malware.

It is listed here as Risky tool, not malware — the concern is the combination of dangerous capabilities and install-time hygiene that puts its own users at risk.

Why it is risky

On npm install, the postinstall hook (scripts/postinstall.mjs) silently injects its own instruction block into ~/.claude/CLAUDE.md, ~/.cursor/rules and ~/.windsurfrules — writing to the AI agent's control surface without explicit consent.

The capabilities it exposes to the agent are high-impact: autonomous movement of funds (supply/withdraw/swap) and autonomous credential login to arbitrary sites with no human approval. A prompt-injection or a mistaken agent step can therefore move money or use stored credentials. Slippage walls (100 bps) and --max-loss-bps exist but do not remove the class of risk.

Behaviours to be aware of
📝postinstall injects an instruction block into ~/.claude/CLAUDE.md + ~/.cursor/rules + ~/.windsurfrules
💸Autonomous fund movement: agentgates earn supply|withdraw, swaps, batch ("several money moves, one approval")
🔑Autonomous site login via a cloud VM: agentgates passwords use --url …/login — "no pairing and no human"
✅First-party network only (agentgates.ai + crypto-spec sites); no hidden exfiltration observed
If you use it
#ActionPriority
1 Install with --ignore-scripts and review scripts/postinstall.mjs + the block it writes to your agent config before trusting it. Recommended
2 Run the agent against a dedicated low-balance wallet and a scoped credential set — never your primary keys/passwords — given the autonomous money/login capability. Recommended

Explicitly not malware: real vendor, first-party-only network, no hidden exfiltration. Catalogued as a Risky tool so users understand the autonomous money/login capability and the silent agent-config injection; excluded from the OSV outputs by design.