ai-intelligent-data-governance

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONNO_CODEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation in SKILL.md instructs the user or agent to clone a repository from an unverified GitHub account (openclaw-skills).
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to execute code (python app.py) that is downloaded from an external source at runtime.
  • [COMMAND_EXECUTION]: The skill lists shell commands for installation and execution, which could be automatically run by an agent, potentially leading to unauthorized system changes.
  • [NO_CODE]: The skill files themselves do not contain any executable code or logic, acting primarily as a guide to external software.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process external data sources for governance, which presents a surface for indirect prompt injection. No boundary markers or sanitization strategies are identified in the provided files to mitigate the risk of instructions embedded within the processed data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 05:56 PM
Security Audit — agent-trust-hub — ai-intelligent-data-governance