nanoclaw-repl

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill metadata exhibits a discrepancy between the provided author context (Brainmetrix) and the 'origin' field (ECC) in the YAML frontmatter. While this may reflect an organization name, it represents an inconsistency in metadata identification.
  • [PROMPT_INJECTION]: The skill describes an architecture susceptible to indirect prompt injection through its session management features. It allows the agent to ingest and process data from external sources and previous history which could contain hidden instructions.
  • Ingestion points: The /search (cross-session search) and /load (dynamic skill loading) commands described in SKILL.md are primary data ingestion vectors.
  • Boundary markers: Absent; there are no instructions provided to wrap retrieved session data or loaded skills in protective delimiters to prevent instruction hijacking.
  • Capability inventory: The skill enables session persistence, model switching, and execution of local logic via scripts/claw.js as referenced in SKILL.md.
  • Sanitization: Absent; the instructions do not include steps for the agent to sanitize or validate the content of sessions or skills before processing them.
  • [COMMAND_EXECUTION]: The skill documentation describes functionality for dynamic execution via the /load command. This feature is intended to extend the REPL environment at runtime, which inherently involves the dynamic loading and potential execution of new logic or skill definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — nanoclaw-repl