openclaw-persona-forge

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Python script (gacha.py) to provide random character combinations. This script uses the standard library to perform calculations and does not access the network or sensitive system files.
  • [SAFE]: The skill manages character generation through structured templates and user-guided prompts. It includes logic for interacting with other authorized image generation skills, including specific instructions to sanitize character names (restricting to alphanumeric characters and hyphens) before using them in file paths to prevent command injection or path traversal.
  • [SAFE]: File creation activities (SOUL.md and IDENTITY.md) are performed at the user's request into specified directories, primarily for the purpose of exporting the generated persona configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:23 PM
Security Audit — agent-trust-hub — openclaw-persona-forge