skills/joelhooks/joelclaw/fleet-ops/Gen Agent Trust Hub

fleet-ops

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a custom command-line tool named joelclaw to perform fleet status and difference checks. The usage is strictly scoped to auditing tasks that do not involve system modification, package installation, or credential manipulation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external hosts via JSON envelopes returned by fleet commands, creating a potential surface for indirect prompt injection if host data is maliciously crafted. However, the skill lacks the high-privilege capabilities (such as arbitrary file writes or network exfiltration) required to weaponize this surface.
  • Ingestion points: Data returned by the joelclaw fleet status and joelclaw fleet diff commands in SKILL.md.
  • Boundary markers: None explicitly defined in the instructions for the ingested JSON data.
  • Capability inventory: The skill is restricted to local read-only commands and does not include subprocess execution of user input, network operations, or file system modifications.
  • Sanitization: No specific sanitization or schema validation logic for the tool output is described in the prompt instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — fleet-ops