gitclaw-backup
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to synchronize the local
/home/node/.openclaw/directory with a remote repository atgithub.com/blessonism/openclaw-backup.git. While this is the stated purpose, it involves sending local workspace data to an external service. - [CREDENTIALS_UNSAFE]: The troubleshooting section recommends running
git credential fill <<< "host=github.com". This command is intended to retrieve and display stored Git credentials; if executed by the agent, it could reveal plain-text authentication tokens or passwords in the agent's output. - [PERSISTENCE]: The skill documentation references a daily cron job (
daily-workspace-backup) that executes at 16:00 UTC. This ensures the backup logic maintains a persistent presence and executes automatically on a schedule. - [COMMAND_EXECUTION]: The skill instructs the agent to execute local shell scripts (
auto_backup.sh) and various system commands includinggit,bash,tail, andrmdirto manage the backup process and logs. - [INDIRECT_PROMPT_INJECTION]: The agent is tasked with reading and displaying output from
git logandgit status. If the repository contains files or commit messages from untrusted external sources, these strings could contain malicious instructions that the agent might inadvertently follow. - Ingestion points: Git commit history (
git log), repository status (git status), and log files (backup.log). - Boundary markers: None provided in the instructions for parsing command output.
- Capability inventory: Shell execution (
bash), file system modification (rmdir), log reading (tail), and network operations viagit push. - Sanitization: No evidence of output sanitization or filtering before processing command results.
Audit Metadata