ai-intelligent-data-governance
Warn
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONNO_CODEPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation in
SKILL.mdinstructs the user or agent to clone a repository from an unverified GitHub account (openclaw-skills). - [REMOTE_CODE_EXECUTION]: The skill provides instructions to execute code (
python app.py) that is downloaded from an external source at runtime. - [COMMAND_EXECUTION]: The skill lists shell commands for installation and execution, which could be automatically run by an agent, potentially leading to unauthorized system changes.
- [NO_CODE]: The skill files themselves do not contain any executable code or logic, acting primarily as a guide to external software.
- [PROMPT_INJECTION]: The skill is designed to ingest and process external data sources for governance, which presents a surface for indirect prompt injection. No boundary markers or sanitization strategies are identified in the provided files to mitigate the risk of instructions embedded within the processed data.
Audit Metadata