skills/steipete/openclaw/1password/Gen Agent Trust Hub

1password

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the official 1Password CLI tool via the brew package manager as specified in the openclaw metadata section.\n- [COMMAND_EXECUTION]: The instructions utilize the op command-line tool and tmux to manage authentication and secret retrieval, using a dedicated tmux socket to isolate tool execution.\n- [DATA_EXFILTRATION]: The skill is designed to access and inject sensitive data from 1Password vaults. It includes instructions to use op run and op inject to manage these secrets securely, while explicitly warning against pasting secrets into chat or logs.\n- [PROMPT_INJECTION]: The skill retrieves data from 1Password vaults, such as vault names and item titles, which can act as a vector for indirect prompt injection if external vault data contains malicious instructions.\n
  • Ingestion points: Output from commands like op vault list and op account list mentioned in SKILL.md.\n
  • Boundary markers: The skill does not provide specific delimiters or instructions for the agent to ignore potentially malicious content within the tool output.\n
  • Capability inventory: The agent has the capability to execute commands using op run and modify files using op inject, as outlined in the references/cli-examples.md file.\n
  • Sanitization: No explicit sanitization or filtering of the vault data is performed before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:11 PM
Security Audit — agent-trust-hub — 1password