gstack-openclaw-ceo-review
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a purely instructional persona designed to guide the agent through a logical review process. It does not contain any code, scripts, or external dependencies.
- [SAFE]: While Section 3 mentions a 'Security & Threat Model,' it is an instruction for the agent to manually evaluate these factors in the user's plan, not an automated process that could be exploited.
- [SAFE]: The skill explicitly forbids code changes and implementation, stating 'Do NOT make any code changes. Do NOT start implementation.' This prevents the agent from taking autonomous actions on the filesystem.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided plans. While theoretically susceptible to instructions hidden within those plans, the skill's rigid structure (11 mandatory sections, one-at-a-time interaction) and the requirement for human opt-in for all changes act as strong mitigations. Severity is safe/low.
- [NO_CODE]: The skill contains no executable components, configuration for external tools, or network-enabled functionality.
Audit Metadata