gstack-openclaw-office-hours
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill performs automated reading of the workspace, existing project documents, and git logs to gather context. This ingestion of untrusted data from the codebase creates a surface for indirect prompt injection where instructions hidden in files or commit messages could influence the agent. • Ingestion points: Phase 1 (Context Gathering) reads workspace docs and git log in SKILL.md. • Boundary markers: Not present; the instructions do not specify delimiters for external content. • Capability inventory: The skill uses git log and codebase search, and has the capability to write to the memory/ directory. It includes a specific prohibition (HARD GATE) against code implementation. • Sanitization: No filtering or sanitization of ingested data is specified.
- [COMMAND_EXECUTION]: To gather context, the skill instructs the agent to execute git log and perform codebase-wide searches.
- [SAFE]: The skill contains references to ycombinator.com for founder applications. These are legitimate resources provided by the author's organization and represent safe external references.
Audit Metadata