openclaw-marketing-skills
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install components from the LeoYeAI/openclaw-marketing-skills GitHub repository and the @xquik/tweetclaw plugin (SKILL.md).
- [PROMPT_INJECTION]: The skill processes untrusted external data from X/Twitter, Google Ads, and Meta Ads APIs, creating a surface for indirect prompt injection.
- Ingestion points: Real-time data feeds from Google Ads, Search Console, Meta Ads, and X/Twitter search results (SKILL.md).
- Boundary markers: No specific delimiters or instructions are defined to separate untrusted external content from agent commands.
- Capability inventory: The skill writes to .agents/product-marketing-context.md and executes additional agent tasks via the openclaw ask command.
- Sanitization: No data validation or sanitization routines are described for the imported external API content.
Audit Metadata