skills/steipete/openclaw/healthcheck/Gen Agent Trust Hub

healthcheck

Warn

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes various system-level tools such as uname, ss, lsof, ufw, firewall-cmd, and pfctl to audit the host network and OS state.- [COMMAND_EXECUTION]: Utilizes the openclaw CLI to perform deep security audits, apply configuration fixes, and check for software updates.- [COMMAND_EXECUTION]: Establishes persistence by offering to schedule periodic security audits and update checks via openclaw cron add.- [EXTERNAL_DOWNLOADS]: Performs external version checks by querying the public NPM registry using npm view.- [COMMAND_EXECUTION]: Proposes and executes state-changing modifications to system-level security controls, including firewall rules, network port exposure, and SSH/RDP configurations.- [PROMPT_INJECTION]: Vulnerable to indirect prompt injection through the ingestion of untrusted system command outputs (e.g., process lists from lsof or network state from ss). Ingestion points: system tool and audit command outputs; Boundary markers: Absent; Capability inventory: firewall management, SSH configuration, task scheduling; Sanitization: Explicitly redacts secrets and tokens from logs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 02:11 PM
Security Audit — agent-trust-hub — healthcheck