openclaw-executive-assistant-webinar

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an untrusted third-party GitHub account (dandenney) to obtain workshop materials.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as unidentified files and exported emails, which could contain instructions to manipulate the agent.
  • Ingestion points: Files in the incoming/ and eml/ directories defined in the workspace.
  • Boundary markers: None explicitly defined in the provided prompt structures.
  • Capability inventory: Data is processed to generate markdown reports; no automated tool execution or network calls are triggered by this content in the provided context.
  • Sanitization: No content validation or sanitization is performed on the ingested files.- [PERSISTENCE]: The skill provides patterns for setting up cron jobs to automate log and summary generation, which creates scheduled execution on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:50 PM
Security Audit — agent-trust-hub — openclaw-executive-assistant-webinar