gstack-openclaw-office-hours

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill performs automated reading of the workspace, existing project documents, and git logs to gather context. This ingestion of untrusted data from the codebase creates a surface for indirect prompt injection where instructions hidden in files or commit messages could influence the agent. • Ingestion points: Phase 1 (Context Gathering) reads workspace docs and git log in SKILL.md. • Boundary markers: Not present; the instructions do not specify delimiters for external content. • Capability inventory: The skill uses git log and codebase search, and has the capability to write to the memory/ directory. It includes a specific prohibition (HARD GATE) against code implementation. • Sanitization: No filtering or sanitization of ingested data is specified.
  • [COMMAND_EXECUTION]: To gather context, the skill instructs the agent to execute git log and perform codebase-wide searches.
  • [SAFE]: The skill contains references to ycombinator.com for founder applications. These are legitimate resources provided by the author's organization and represent safe external references.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:39 PM
Security Audit — agent-trust-hub — gstack-openclaw-office-hours