skills/joelhooks/joelclaw/monitor/Gen Agent Trust Hub

monitor

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, creating a surface for indirect prompt injection.
  • Ingestion points: The skill fetches content from external URLs, including Atom/RSS feeds, GitHub repositories, and general web pages as described in the Subscription Types section of SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to ignore potentially malicious instructions embedded within the fetched feed content or web pages.
  • Capability inventory: The skill uses the joelclaw CLI for resource management and relies on an Inngest-based backend (packages/system-bus/src/inngest/functions/subscriptions.ts) to trigger LLM-based summarization (subscription/summarize).
  • Sanitization: The skill instructions do not specify any sanitization, filtering, or validation steps for the external content before it is passed to the LLM for summarization.
  • [COMMAND_EXECUTION]: The skill uses a specialized CLI tool, joelclaw, to perform its primary functions. These commands are executed within the agent's environment to list, add, remove, and check subscriptions.
  • [EXTERNAL_DOWNLOADS]: The skill is intended to interact with external web resources, including GitHub APIs and various feed formats (RSS/Atom), to monitor for changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:02 PM
Security Audit — agent-trust-hub — monitor