model-fallback
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/model-error-wrapper.shexecutes arbitrary shell commands provided via the--commandargument usingbash -c "$COMMAND". This is a core feature of the utility but allows for the execution of any shell-compatible code passed to the wrapper. - [COMMAND_EXECUTION]: The skill relies extensively on executing external system commands and scripts, including
openclaw,notify-send, and custom scripts located in~/.openclaw/scripts/to manage model status and alerts. - [INDIRECT_PROMPT_INJECTION]: The skill captures error messages from model API responses or command outputs and passes them to
scripts/auto-switch-handler.sh. These externally sourced messages are logged and processed to determine switching logic. - Ingestion points: Standard error and output streams of the model commands are captured in
model-error-wrapper.shand passed to the handler via the--error-messageflag. - Boundary markers: No explicit delimiters or sanitization routines are used when processing the captured error strings.
- Capability inventory: The skill has access to shell execution (
bash -c), file system writes for logging, and potentially network access if the user implements the suggested Telegram alert scripts. - Sanitization: The error messages are interpolated into log commands and passed between scripts without escaping, which could lead to issues if an attacker can control the error output of a failed model request.
Audit Metadata