joelclaw-web
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to execute system-level commands to populate the network status page.
- Evidence: The 'Network Page' section in SKILL.md instructs the agent to use kubectl get pods, tailscale status, and launchctl print. These are used specifically for infrastructure monitoring and are subject to the skill's internal OPSEC rules.
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes and publishes user-provided or externally sourced content.
- Ingestion points: Data is ingested from user prompts for article topics and from Convex contentResources.
- Boundary markers: No specific delimiters are used to wrap untrusted content.
- Capability inventory: The skill can upsert to the Convex database, perform file system writes for media assets, and trigger network revalidation via POST /api/revalidate.
- Sanitization: The skill performs layout-based transformations but lacks dedicated security sanitization for ingested content strings.
Audit Metadata