openclaw-executive-assistant-webinar
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an untrusted third-party GitHub account (dandenney) to obtain workshop materials.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as unidentified files and exported emails, which could contain instructions to manipulate the agent.
- Ingestion points: Files in the
incoming/andeml/directories defined in the workspace. - Boundary markers: None explicitly defined in the provided prompt structures.
- Capability inventory: Data is processed to generate markdown reports; no automated tool execution or network calls are triggered by this content in the provided context.
- Sanitization: No content validation or sanitization is performed on the ingested files.- [PERSISTENCE]: The skill provides patterns for setting up cron jobs to automate log and summary generation, which creates scheduled execution on the host system.
Audit Metadata