gitclaw-backup

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to synchronize the local /home/node/.openclaw/ directory with a remote repository at github.com/blessonism/openclaw-backup.git. While this is the stated purpose, it involves sending local workspace data to an external service.
  • [CREDENTIALS_UNSAFE]: The troubleshooting section recommends running git credential fill <<< "host=github.com". This command is intended to retrieve and display stored Git credentials; if executed by the agent, it could reveal plain-text authentication tokens or passwords in the agent's output.
  • [PERSISTENCE]: The skill documentation references a daily cron job (daily-workspace-backup) that executes at 16:00 UTC. This ensures the backup logic maintains a persistent presence and executes automatically on a schedule.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local shell scripts (auto_backup.sh) and various system commands including git, bash, tail, and rmdir to manage the backup process and logs.
  • [INDIRECT_PROMPT_INJECTION]: The agent is tasked with reading and displaying output from git log and git status. If the repository contains files or commit messages from untrusted external sources, these strings could contain malicious instructions that the agent might inadvertently follow.
  • Ingestion points: Git commit history (git log), repository status (git status), and log files (backup.log).
  • Boundary markers: None provided in the instructions for parsing command output.
  • Capability inventory: Shell execution (bash), file system modification (rmdir), log reading (tail), and network operations via git push.
  • Sanitization: No evidence of output sanitization or filtering before processing command results.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 01:43 PM