gstack-openclaw-investigate

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted input including error messages and stack traces. While this presents an injection surface, the skill includes explicit mitigation instructions to sanitize data before external use.
  • Ingestion points: User-provided error messages and stack traces (Phase 1).
  • Boundary markers: Instructs the agent to sanitize error categories and strip sensitive details (Phase 2).
  • Capability inventory: Execution of git log and file system writes for bug fixing (Phase 4).
  • Sanitization: Instructions clearly mandate stripping hostnames, IPs, file paths, SQL, and customer data (Phase 2).
  • [COMMAND_EXECUTION]: The skill uses git log to investigate recent changes, which is a standard and safe development tool operation within the context of debugging.
  • [SAFE]: The skill adheres to secure development practices by emphasizing root cause analysis over symptomatic fixes and requiring verification of all changes through tests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:04 PM
Security Audit — agent-trust-hub — gstack-openclaw-investigate