monitor
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, creating a surface for indirect prompt injection.
- Ingestion points: The skill fetches content from external URLs, including Atom/RSS feeds, GitHub repositories, and general web pages as described in the
Subscription Typessection ofSKILL.md. - Boundary markers: There are no explicit instructions or delimiters provided to the agent to ignore potentially malicious instructions embedded within the fetched feed content or web pages.
- Capability inventory: The skill uses the
joelclawCLI for resource management and relies on an Inngest-based backend (packages/system-bus/src/inngest/functions/subscriptions.ts) to trigger LLM-based summarization (subscription/summarize). - Sanitization: The skill instructions do not specify any sanitization, filtering, or validation steps for the external content before it is passed to the LLM for summarization.
- [COMMAND_EXECUTION]: The skill uses a specialized CLI tool,
joelclaw, to perform its primary functions. These commands are executed within the agent's environment to list, add, remove, and check subscriptions. - [EXTERNAL_DOWNLOADS]: The skill is intended to interact with external web resources, including GitHub APIs and various feed formats (RSS/Atom), to monitor for changes.
Audit Metadata