gateway-diagnose
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a variety of system commands to perform diagnostics, including
launchctlfor service management,kubectlfor Kubernetes cluster status,colimafor container runtime status, and a customjoelclawCLI. It also performs a reachability check usingcurlto the Anthropic API with a dummy authentication key. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and display diagnostic logs and session transcripts, which represents an attack surface for indirect prompt injection if the logs contain malicious instructions.
- Ingestion points: Log files (
/tmp/joelclaw/gateway.log,/tmp/joelclaw/gateway.err) and session transcripts (~/.joelclaw/sessions/gateway/*.jsonl). - Boundary markers: None identified in the diagnostic procedures; logs are read directly using
tailorcat. - Capability inventory: The skill has access to execute shell commands, perform Kubernetes operations (
kubectl exec), and make network requests (curl). - Sanitization: No explicit sanitization or filtering of the log content is described before it is processed by the agent.
Audit Metadata