skills/joelhooks/joelclaw/discovery/Gen Agent Trust Hub

discovery

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the joelclaw CLI tool to capture discoveries. It passes user-provided URLs and context strings as data payloads to shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill triggers a background pipeline that performs automated downloads and repository cloning of external sources provided by the user via URLs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs (articles, repositories, and social media posts), creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded in the captured content.
  • Ingestion points: External URLs shared by the user in chat or auto-captured from specific Slack channels as described in SKILL.md.
  • Boundary markers: The skill instructions do not specify the use of delimiters or explicit instructions to ignore embedded commands within the captured data.
  • Capability inventory: The skill facilitates command execution via the joelclaw CLI, performs local file system writes to a Vault, and initiates network-based enrichment tasks.
  • Sanitization: The instructions do not describe any sanitization, validation, or filtering of the content retrieved from external sources before it is summarized or stored.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — discovery