clawsweeper-status
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The bash script
scripts/clawsweeper-status.shmakes a network request tohttps://clawsweeper.openclaw.ai/api/exact-review-queue(or a URL defined by theCLAWSWEEPER_EXACT_REVIEW_QUEUE_URLenvironment variable) to fetch queue status information. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub, including issue comments, pull request titles, and workflow run names, which are then reported to the user.\n
- Ingestion points: Data is fetched via
gh apiandgh pr listwithin thescripts/clawsweeper-status.shscript.\n - Boundary markers: The skill instructions in
SKILL.mddo not specify delimiters or instructions for the agent to ignore embedded commands within the fetched GitHub content.\n - Capability inventory: The skill uses the
ghCLI for repository interaction andcurlfor network requests.\n - Sanitization: The script uses
jqto clean and truncate lines for display purposes, but it does not perform security-specific sanitization to prevent prompt injection from the processed GitHub content.
Audit Metadata