skills/rawknee-69/beta-claw/status/Gen Agent Trust Hub

status

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: There are inconsistencies in the skill's metadata. The file identifies the author as 'betaclaw', which differs from the provided developer context of 'rawknee-69'. Additionally, the YAML version (1.0.0) conflicts with the version displayed in the dashboard output template (2.0.0). These discrepancies can be used to mislead users or automated systems regarding the skill's origin and state.
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to report status and message counts from external channels, including WhatsApp, Telegram, and Discord. This indicates that the agent's runtime context interacts with untrusted data from these external platforms, creating a potential vector for indirect prompt injection.
  • Ingestion points: External messaging platforms (WhatsApp, Telegram, Discord) referenced in the 'Channels' reporting section of SKILL.md.
  • Boundary markers: The instructions do not specify any boundary markers or instructions to the agent to disregard embedded commands within data from these external channels.
  • Capability inventory: The skill utilizes the 'run_code' and 'read_file' tools (as defined in the frontmatter) to collect system metrics and health data.
  • Sanitization: There is no evidence of data sanitization or filtering logic applied to content received from external communication channels before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:30 PM
Security Audit — agent-trust-hub — status