agent-autonomy-kit-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The kit utilizes openclaw cron add to create scheduled tasks for automated reporting and work triggers. This establishes persistent execution patterns that run unsupervised.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the tasks/QUEUE.md file, which the agent reads to determine its next tasks. The skill includes embedded instructions (guardrails) to prevent the agent from executing high-risk commands derived from this untrusted input.
  • [DATA_EXFILTRATION]: The workflow involves posting progress updates to configured team channels (Discord/Slack), which entails sending project-related data to external services.
  • [EXTERNAL_DOWNLOADS]: The documentation references external GitHub repositories for installation and dependency management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:30 PM
Security Audit — agent-trust-hub — agent-autonomy-kit-hardened