signal-friction-scan

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session history and transcripts to identify patterns, which constitutes a significant attack surface for indirect prompt injection.
  • Ingestion points: Session history and transcript data are ingested via joelclaw sessions signals, joelclaw sessions search, and joelclaw session inspect.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the processed transcript data.
  • Capability inventory: The skill has the capability to execute shell commands (find, rg, xargs, joelclaw) and can propose or create new skill assets (Pass 2).
  • Sanitization: While the skill instructs the agent not to include raw transcript dumps or capture secrets, there is no technical sanitization or validation of the ingested session content described.
  • [COMMAND_EXECUTION]: The skill uses shell commands that incorporate user-provided or session-derived strings, which could lead to command injection if not properly handled by the agent.
  • Evidence: Commands such as joelclaw sessions search "<candidate query>" and rg -n "...|<candidate-term>" interpolate variables directly into the command line.
  • Tool Usage: The skill utilizes the joelclaw CLI tool, which appears to be a local vendor resource associated with the author, to perform session analysis and asset management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — signal-friction-scan