review-clawhub-profile-proposal
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references a benchmarking dataset located at
https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl. HuggingFace is a well-known service for hosting models and datasets, and this reference is part of the legitimate benchmarking process described in the workflow. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and review untrusted external security proposals (
proposals/<GHSA-ID>/clawscan.yml). This represents a vulnerability surface where malicious content could attempt to influence the agent's behavior during the review process, although the workflow includes manual validation steps to mitigate direct obedience.
Audit Metadata