openclaw-executive-assistant-local

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill describes workflows for processing untrusted external data (emails and unknown files) which introduces an indirect prompt injection surface.
  • Ingestion points: Files in folders like 01-data-intake-review/incoming/ and 03-offline-communications-triage/eml/ are passed to the AI.
  • Boundary markers: The prompt templates provided do not include specific delimiters or instructions to ignore embedded commands in the data.
  • Capability inventory: The AI is tasked with generating markdown summaries and action items.
  • Sanitization: No data sanitization steps are defined for the input files.
  • [COMMAND_EXECUTION]: The skill provides examples for automating tasks using local shell scripts and cron jobs. These scripts are user-configurable templates for local automation and do not download or execute remote code from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 08:46 AM
Security Audit — agent-trust-hub — openclaw-executive-assistant-local