openclaw-executive-assistant-local
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill describes workflows for processing untrusted external data (emails and unknown files) which introduces an indirect prompt injection surface.
- Ingestion points: Files in folders like
01-data-intake-review/incoming/and03-offline-communications-triage/eml/are passed to the AI. - Boundary markers: The prompt templates provided do not include specific delimiters or instructions to ignore embedded commands in the data.
- Capability inventory: The AI is tasked with generating markdown summaries and action items.
- Sanitization: No data sanitization steps are defined for the input files.
- [COMMAND_EXECUTION]: The skill provides examples for automating tasks using local shell scripts and cron jobs. These scripts are user-configurable templates for local automation and do not download or execute remote code from untrusted sources.
Audit Metadata