nanoclaw-traffic-guardian
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
SKILL.mdfile includes a verification script that fetches release artifacts from the vendor's GitHub repository (prompt-security/clawsec). This is part of a secure-by-default installation process for verifying package integrity. - [INDIRECT_PROMPT_INJECTION]: The
SPEC.mdfile defines a surface for monitoring network traffic, which involves ingesting untrusted data. The specification mitigates this by requiring mandatory snippet redaction, bounded scan limits, and isolating the monitoring logic on the host side, keeping the container-side MCP tools restricted to redacted findings. Ingestion points include HTTP/HTTPS traffic monitoring; boundaries are defined by IPC task handling and host-service isolation; capabilities include MCP tools for status and findings; and sanitization is enforced through mandatory secret redaction.
Audit Metadata