openclaw-marketing-skills
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the user to install components from third-party sources outside the author's infrastructure. It uses
clawhub install LeoYeAI/openclaw-marketing-skillsandgit clone https://github.com/LeoYeAI/openclaw-marketing-skills.gitfor installation. Additionally, it prompts the installation of the@xquik/tweetclawplugin for X/Twitter functionality. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various external platforms, creating a surface for indirect prompt injection where malicious instructions embedded in web content or social media posts could influence agent behavior.
- Ingestion points: The
page-croandseo-auditskills analyze content from user-specified URLs. Thex-twitter-connectskill ingests live tweet search results and conversation threads. The data connectors for Google and Meta ingest performance data and social signals. - Boundary markers: The instructions do not specify any boundary markers or delimiters to separate untrusted external data from the agent's core instructions.
- Capability inventory: The skill suite possesses broad capabilities, including writing files to the local file system (product marketing context), performing network operations through various data connectors, and generating content like emails and social media posts.
- Sanitization: There is no documentation of sanitization, validation, or filtering processes for the data retrieved from external sources before it is processed by the agent.
Audit Metadata