skills/joelhooks/joelclaw/recall/Gen Agent Trust Hub

recall

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands to perform deep searches across the local system. It uses standard utilities such as rg (ripgrep), grep, and ls, as well as a specialized CLI tool joelclaw (a vendor-specific resource) to query memory sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize content from external, untrusted sources including markdown notes in ~/Vault/, .svx files in ~/.brain, and previous session transcripts.
  • Ingestion points: Files located in ~/.brain and ~/Vault/, media metadata in /tmp/joelclaw-media/, and session data retrieved via joelclaw CLI.
  • Boundary markers: None identified. The instructions do not define delimiters or provide the agent with guidance to ignore potential instructions embedded within the retrieved notes or media tags.
  • Capability inventory: The skill possesses filesystem access (rg, grep, ls) and access to runtime telemetry and event logs via the joelclaw tool.
  • Sanitization: None. The workflow instructs the agent to synthesize findings and present them directly into the context, which could allow malicious instructions stored in notes to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — recall