nemoclaw-wakeup

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override the agent's standard behavior and memory by mandating that it 'Do EXACTLY what it says' and 'Do NOT use cached or remembered instructions from previous sessions.' This strict adherence to external content facilitates the execution of potentially malicious instructions if the target file is compromised.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface where untrusted data is processed as instructions.
  • Ingestion points: The agent is directed to read and follow content from __WAKEUP_MD_PATH__, /sandbox/.openclaw/workspace/WAKEUP.md, or /sandbox/.openclaw-data/workspace/WAKEUP.md.
  • Boundary markers: There are no boundary markers, delimiters, or 'ignore embedded instructions' warnings present in the skill's instructions for handling the content of the task file.
  • Capability inventory: The agent has the ability to use the read and edit tools on the task file, and is authorized to invoke 'any installed skills' such as gog, planet, and brave based on the file's content.
  • Sanitization: No sanitization, validation, or filtering of the external file's content is implemented before the agent interprets it as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 08:28 AM
Security Audit — agent-trust-hub — nemoclaw-wakeup