ecc-claude-ra-qm-team-risk-management-specialist

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as its core workflow involves ingesting external guidance and translating it into executable actions.
  • Ingestion points: The agent is instructed to read content from reference paths specified in references/upstream-path.txt.
  • Boundary markers: The instructions do not provide delimiters or security constraints to distinguish between guidance data and potential malicious instructions embedded within the reference files.
  • Capability inventory: The skill enables a direct path to tool execution by instructing the agent to 'Translate to OpenClaw tool-backed steps' and 'Execute incrementally' based on the data read.
  • Sanitization: There is no evidence of logic to sanitize, validate, or filter the reference content before it influences the agent's execution steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 03:13 AM
Security Audit — agent-trust-hub — ecc-claude-ra-qm-team-risk-management-specialist