fleet-ops
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a custom command-line tool named
joelclawto perform fleet status and difference checks. The usage is strictly scoped to auditing tasks that do not involve system modification, package installation, or credential manipulation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external hosts via JSON envelopes returned by fleet commands, creating a potential surface for indirect prompt injection if host data is maliciously crafted. However, the skill lacks the high-privilege capabilities (such as arbitrary file writes or network exfiltration) required to weaponize this surface.
- Ingestion points: Data returned by the
joelclaw fleet statusandjoelclaw fleet diffcommands in SKILL.md. - Boundary markers: None explicitly defined in the instructions for the ingested JSON data.
- Capability inventory: The skill is restricted to local read-only commands and does not include subprocess execution of user input, network operations, or file system modifications.
- Sanitization: No specific sanitization or schema validation logic for the tool output is described in the prompt instructions.
Audit Metadata