ecc-claude-ra-qm-team-risk-management-specialist
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as its core workflow involves ingesting external guidance and translating it into executable actions.
- Ingestion points: The agent is instructed to read content from reference paths specified in
references/upstream-path.txt. - Boundary markers: The instructions do not provide delimiters or security constraints to distinguish between guidance data and potential malicious instructions embedded within the reference files.
- Capability inventory: The skill enables a direct path to tool execution by instructing the agent to 'Translate to OpenClaw tool-backed steps' and 'Execute incrementally' based on the data read.
- Sanitization: There is no evidence of logic to sanitize, validate, or filter the reference content before it influences the agent's execution steps.
Audit Metadata