skills/openclaw/acpx/crabbox/Gen Agent Trust Hub

crabbox

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to manage remote environments, including tools like crabbox, blacksmith, pnpm, and system utilities.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the Crabbox CLI via Homebrew and accessing vendor-hosted services at openclaw.ai.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from remote command outputs and terminal captures. Evidence chain: 1. Ingestion points: Remote command logs, JSON summaries, and tmux pane captures. 2. Boundary markers: No explicit delimiters defined for remote content. 3. Capability inventory: Access to shell execution and network operations via the Crabbox CLI. 4. Sanitization: Instructions suggest redacting output via sed and using isolated state directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:33 AM
Security Audit — agent-trust-hub — crabbox