recall
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands to perform deep searches across the local system. It uses standard utilities such as
rg(ripgrep),grep, andls, as well as a specialized CLI tooljoelclaw(a vendor-specific resource) to query memory sources. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize content from external, untrusted sources including markdown notes in
~/Vault/,.svxfiles in~/.brain, and previous session transcripts. - Ingestion points: Files located in
~/.brainand~/Vault/, media metadata in/tmp/joelclaw-media/, and session data retrieved viajoelclawCLI. - Boundary markers: None identified. The instructions do not define delimiters or provide the agent with guidance to ignore potential instructions embedded within the retrieved notes or media tags.
- Capability inventory: The skill possesses filesystem access (
rg,grep,ls) and access to runtime telemetry and event logs via thejoelclawtool. - Sanitization: None. The workflow instructs the agent to synthesize findings and present them directly into the context, which could allow malicious instructions stored in notes to influence agent behavior.
Audit Metadata