crabbox
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands to manage remote environments, including tools like crabbox, blacksmith, pnpm, and system utilities.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Crabbox CLI via Homebrew and accessing vendor-hosted services at openclaw.ai.
- [PROMPT_INJECTION]: The skill ingests untrusted data from remote command outputs and terminal captures. Evidence chain: 1. Ingestion points: Remote command logs, JSON summaries, and tmux pane captures. 2. Boundary markers: No explicit delimiters defined for remote content. 3. Capability inventory: Access to shell execution and network operations via the Crabbox CLI. 4. Sanitization: Instructions suggest redacting output via sed and using isolated state directories.
Audit Metadata