skills/clawic/skills/Football/Gen Agent Trust Hub

Football

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external information such as 'public football facts,' 'stats,' and 'public reports.' This creates a surface for indirect prompt injection attacks where malicious instructions hidden in external data could influence the agent.\n
  • Ingestion points: External match statistics, scouting reports, and tactical information from public web sources (documented in SKILL.md).\n
  • Boundary markers: The skill does not provide clear delimiters or 'ignore' instructions for the agent when processing external tactical data.\n
  • Capability inventory: The skill has the capability to write and modify persistent markdown files within the user's ~/football/ directory.\n
  • Sanitization: No explicit validation or filtering logic is mentioned for data fetched from external sources.\n- [NO_CODE]: The skill consists entirely of markdown documentation and JSON metadata. No executable files (such as .py, .js, or .sh) are included, which effectively mitigates the risk of code-based security threats.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 08:02 AM
Security Audit — agent-trust-hub — Football