skills/firecrawl/openclaw/eightctl/Gen Agent Trust Hub

eightctl

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill metadata specifies an installation step that downloads and installs the eightctl binary from an external GitHub repository (github.com/steipete/eightctl) using the Go package manager. This source is not from a recognized trusted entity.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through eightctl status and list commands in SKILL.md. It lacks explicit boundary markers to delimit this external data from agent instructions. The capability inventory includes hardware control such as changing temperatures and setting alarms. No sanitization or validation of the command-line output is defined before processing, creating a potential surface for instructions embedded in device status to influence the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 07:53 PM
Security Audit — agent-trust-hub — eightctl