openclaw-persona-forge

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled Python script (gacha.py) using the local python3 interpreter to generate randomized character attributes from a hardcoded list of traits.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-supplied character ideas and existing persona drafts to generate new files (SOUL.md and IDENTITY.md). The ingestion occurs in the initial guidance step and the final output generation. While the skill lacks explicit boundary markers to delimit user input, it applies alphanumeric sanitization to filenames and is limited to creative text generation within the user's local workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — openclaw-persona-forge