nanoclaw-repl

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection through its data processing features. • Ingestion points: The agent ingests data from persistent markdown-backed sessions and cross-session search results (SKILL.md). • Boundary markers: There are no instructions for using delimiters or boundary markers to distinguish untrusted session content from system instructions. • Capability inventory: The skill includes commands for dynamic skill loading (/load) and model switching (/model) (SKILL.md). • Sanitization: No validation or sanitization logic is described for data processed from existing sessions.
  • [COMMAND_EXECUTION]: The skill instructions define a command-based interface for dynamic execution of instructions. • Evidence: The '/load' command is explicitly provided for dynamic skill loading during runtime (SKILL.md). • Mitigation: The skill mandates extension rules that require zero external runtime dependencies and local, deterministic command handlers, which limits the attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:10 AM
Security Audit — agent-trust-hub — nanoclaw-repl