joelclaw-system-check

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The diagnostic scripts access highly sensitive configuration and credential files, including ~/.joelclaw/auth.json (containing authentication tokens) and ~/.talos/config (Kubernetes/Talos cluster configuration). While the scripts attempt to redact these secrets from their own output, the raw files are accessed directly during execution.
  • [COMMAND_EXECUTION]: The skill executes a wide range of system commands and local bash scripts for diagnostic purposes, including launchctl for service management, kubectl for cluster operations, and ssh for remote connectivity checks on other machines (blaine, panda). It also runs test suites via bun test and performs type checks with tsc.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize session transcripts from ~/.codex and session search results. These transcripts contain previous agent interactions, which could potentially contain malicious instructions that influence the agent's behavior in the current session.
  • Ingestion points: The files ~/.codex/session_index.jsonl, ~/.codex/rollout-*.jsonl, and the results from the joelclaw sessions search command.
  • Boundary markers: The skill does not implement explicit delimiters or instruction-bypass warnings when processing these extracted transcripts.
  • Capability inventory: The skill has the ability to execute shell commands, perform network probes, and access the local filesystem.
  • Sanitization: No sanitization or filtering is applied to the content of the transcripts themselves, creating a surface for prompt injection.
  • [DYNAMIC_EXECUTION]: The scripts/postboot.sh script executes an embedded Python snippet using a heredoc (`python3
  • <<'PY'`) to perform authenticated health checks on internal network services.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to repair the pi-tools extension by running bun add for several third-party Node.js packages, including @sinclair/typebox, @mariozechner/pi-coding-agent, and @earendil-works/pi-tui.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — joelclaw-system-check