discovery
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
joelclawCLI tool to capture discoveries. It passes user-provided URLs and context strings as data payloads to shell commands. - [EXTERNAL_DOWNLOADS]: The skill triggers a background pipeline that performs automated downloads and repository cloning of external sources provided by the user via URLs.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs (articles, repositories, and social media posts), creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in the captured content.
- Ingestion points: External URLs shared by the user in chat or auto-captured from specific Slack channels as described in
SKILL.md. - Boundary markers: The skill instructions do not specify the use of delimiters or explicit instructions to ignore embedded commands within the captured data.
- Capability inventory: The skill facilitates command execution via the
joelclawCLI, performs local file system writes to a Vault, and initiates network-based enrichment tasks. - Sanitization: The instructions do not describe any sanitization, validation, or filtering of the content retrieved from external sources before it is summarized or stored.
Audit Metadata