nanoclaw-repl

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill provides a /load command intended for dynamic skill loading at runtime. This functionality allows the environment to load and integrate additional instructions or logic from computed paths, which can be leveraged to change the agent's execution flow or behavior without static oversight.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages persistent markdown-backed sessions, which serve as the primary ingestion point for data within the REPL environment. This creates a vulnerability where untrusted content stored in session history could be interpreted as instructions in subsequent turns.
  • Ingestion points: Persistent markdown session files (database) and the /search functionality which retrieves historical content.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content are defined in the operating guidance.
  • Capability inventory: The system includes commands for model switching (/model), dynamic loading (/load), and file exports, representing a significant capability surface if influenced by malicious input.
  • Sanitization: The instructions do not specify any validation, escaping, or sanitization protocols for the data stored within the markdown-backed sessions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — nanoclaw-repl