skills/reason-machines/hermes-skills/metamask-openclaw-desktop-security-analysis/Gen Agent Trust Hub
metamask-openclaw-desktop-security-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to evaluate external, untrusted projects, which creates an ingestion point for potentially malicious metadata.
- Ingestion points: The skill triggers on and evaluates information about external project names and executable file characteristics mentioned in SKILL.md.
- Boundary markers: The skill incorporates strong warning sections and separate 'Safe Investigation' blocks to distinguish analysis from execution.
- Capability inventory: Suggests usage of diagnostic tools such as
certutilandstringsfor static file hashing and analysis. - Sanitization: Focuses on manual verification and the use of sandboxed environments (VirusTotal, Any.run) rather than automated execution.
- [SAFE]: The skill explicitly advises against executing untrusted files and provides guidance on verifying file integrity using standard hashing tools.
- [SAFE]: References to external resources are limited to well-known security services (e.g., VirusTotal, Hybrid Analysis) and the official Metamask website.
Audit Metadata