gateway
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The gateway daemon is designed to ingest and process data from external communication channels including Telegram, Slack, and webhooks. This creates a surface where external inputs could attempt to inject instructions into the agent's context. 1. Ingestion points: Data enters the system via Redis subscriptions (packages/gateway/src/channels/redis.ts), a Telegram bot interface, and Slack signal ingestion. 2. Boundary markers: The instructions include a specific 'Gateway context refresh scoping' (ADR-0204) section that warns the agent not to treat automated digests or event wrappers as recall seeds. 3. Capability inventory: The skill utilizes several CLI tools, including joelclaw, kubectl, colima, and vercel, for system monitoring and deployment verification. 4. Sanitization: The skill references packages/gateway/src/operator-relay.ts as a heuristics surface for normalizing and routing signals.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform operations using the joelclaw CLI and system tools. Specifically, it describes a 'tool-budget checkpoint tripwire' that forces checkpoints when tool limits are exceeded, and an 'automatic post-push deploy verification' that runs vercel ls. These are operational commands used for maintenance and safety verification of the managed gateway service.
Audit Metadata