gstack-openclaw-retro

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to gather repository statistics, including git fetch, git log, git shortlog, and git ls-files. These commands are used to extract timestamps, author names, and file change statistics.
  • [DATA_EXFILTRATION]: The skill accesses local user identity information by running git config user.name and git config user.email. This data is incorporated into the generated report for personalization. While no external network exfiltration was detected, it involves the exposure of personally identifiable information (PII).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted commit messages and metadata from the git history to generate a narrative retrospective, which presents a surface for indirect prompt injection attacks. (1) Ingestion points: Commit subjects, author names, and file paths are retrieved from the repository using git log. (2) Boundary markers: The skill does not define specific delimiters or instructions to treat commit messages as untrusted data or to ignore embedded commands. (3) Capability inventory: The skill has the capability to execute shell commands via git and write JSON files to the local memory/ directory. (4) Sanitization: There is no evidence of sanitization or validation of the commit data before it is processed by the agent to create the final narrative.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:05 PM
Security Audit — agent-trust-hub — gstack-openclaw-retro