openclaw-marketing-skills

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to install components from third-party sources outside the author's infrastructure. It uses clawhub install LeoYeAI/openclaw-marketing-skills and git clone https://github.com/LeoYeAI/openclaw-marketing-skills.git for installation. Additionally, it prompts the installation of the @xquik/tweetclaw plugin for X/Twitter functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from various external platforms, creating a surface for indirect prompt injection where malicious instructions embedded in web content or social media posts could influence agent behavior.
  • Ingestion points: The page-cro and seo-audit skills analyze content from user-specified URLs. The x-twitter-connect skill ingests live tweet search results and conversation threads. The data connectors for Google and Meta ingest performance data and social signals.
  • Boundary markers: The instructions do not specify any boundary markers or delimiters to separate untrusted external data from the agent's core instructions.
  • Capability inventory: The skill suite possesses broad capabilities, including writing files to the local file system (product marketing context), performing network operations through various data connectors, and generating content like emails and social media posts.
  • Sanitization: There is no documentation of sanitization, validation, or filtering processes for the data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:50 PM
Security Audit — agent-trust-hub — openclaw-marketing-skills