nanoclaw-repl
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection through its data processing features. • Ingestion points: The agent ingests data from persistent markdown-backed sessions and cross-session search results (SKILL.md). • Boundary markers: There are no instructions for using delimiters or boundary markers to distinguish untrusted session content from system instructions. • Capability inventory: The skill includes commands for dynamic skill loading (/load) and model switching (/model) (SKILL.md). • Sanitization: No validation or sanitization logic is described for data processed from existing sessions.
- [COMMAND_EXECUTION]: The skill instructions define a command-based interface for dynamic execution of instructions. • Evidence: The '/load' command is explicitly provided for dynamic skill loading during runtime (SKILL.md). • Mitigation: The skill mandates extension rules that require zero external runtime dependencies and local, deterministic command handlers, which limits the attack surface.
Audit Metadata