firm-ecosystem-audit-pack
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires 'mcp-openclaw-extensions >= 3.0.0', an external dependency from an unknown source not associated with the author or trusted vendors.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface through input parameters. 1. Ingestion points: The tools 'openclaw_mcp_firewall_check' and 'openclaw_rag_pipeline_check' read data from a 'config_path' provided at runtime in SKILL.md. 2. Boundary markers: No delimiters or instructions are present to prevent the agent from following malicious commands inside config files. 3. Capability inventory: The tools perform security-sensitive auditing tasks such as firewall and sandbox execution checks. 4. Sanitization: No evidence of input validation or sanitization is provided.
- [NO_CODE]: No executable code is provided within the skill package; all logic resides in the external dependency.
Audit Metadata