gstack-openclaw-retro
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to gather repository statistics, including
git fetch,git log,git shortlog, andgit ls-files. These commands are used to extract timestamps, author names, and file change statistics. - [DATA_EXFILTRATION]: The skill accesses local user identity information by running
git config user.nameandgit config user.email. This data is incorporated into the generated report for personalization. While no external network exfiltration was detected, it involves the exposure of personally identifiable information (PII). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commit messages and metadata from the git history to generate a narrative retrospective, which presents a surface for indirect prompt injection attacks. (1) Ingestion points: Commit subjects, author names, and file paths are retrieved from the repository using
git log. (2) Boundary markers: The skill does not define specific delimiters or instructions to treat commit messages as untrusted data or to ignore embedded commands. (3) Capability inventory: The skill has the capability to execute shell commands viagitand write JSON files to the localmemory/directory. (4) Sanitization: There is no evidence of sanitization or validation of the commit data before it is processed by the agent to create the final narrative.
Audit Metadata