signal-friction-scan
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes session history and transcripts to identify patterns, which constitutes a significant attack surface for indirect prompt injection.
- Ingestion points: Session history and transcript data are ingested via
joelclaw sessions signals,joelclaw sessions search, andjoelclaw session inspect. - Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the processed transcript data.
- Capability inventory: The skill has the capability to execute shell commands (
find,rg,xargs,joelclaw) and can propose or create new skill assets (Pass 2). - Sanitization: While the skill instructs the agent not to include raw transcript dumps or capture secrets, there is no technical sanitization or validation of the ingested session content described.
- [COMMAND_EXECUTION]: The skill uses shell commands that incorporate user-provided or session-derived strings, which could lead to command injection if not properly handled by the agent.
- Evidence: Commands such as
joelclaw sessions search "<candidate query>"andrg -n "...|<candidate-term>"interpolate variables directly into the command line. - Tool Usage: The skill utilizes the
joelclawCLI tool, which appears to be a local vendor resource associated with the author, to perform session analysis and asset management.
Audit Metadata