skills/akillness/jeo-skills/clawteam/Gen Agent Trust Hub

clawteam

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface where untrusted data enters the agent context and is used in command execution.\n
  • Ingestion points: User-provided task descriptions and goal strings in SKILL.md and scripts/spawn-team.sh.\n
  • Boundary markers: Absent; inputs are interpolated directly into shell commands.\n
  • Capability inventory: The skill can execute subprocesses and manage tmux sessions via the clawteam CLI, with access to Bash and file system tools.\n
  • Sanitization: No escaping or validation of the input strings is implemented before they are passed to the spawn commands.\n- [COMMAND_EXECUTION]: The skill uses Bash scripts to perform environment checks (e.g., verifying python3, tmux, and git versions) and to execute worker orchestration commands through the clawteam CLI. These operations are consistent with the skill's intended purpose.\n- [EXTERNAL_DOWNLOADS]: The installation script (scripts/install.sh) fetches the clawteam package from the Python Package Index (PyPI). It also suggests installing official agent CLIs like @anthropic-ai/claude-code and @openai/codex from the npm registry.\n- [SAFE]: The skill demonstrates secure handling of sensitive information by using placeholders (e.g., MOONSHOT_API_KEY=***) in its configuration examples and documentation, avoiding the exposure of actual credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 01:52 PM
Security Audit — agent-trust-hub — clawteam