consulting-analysis
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script for format conversion located at /root/.openclaw/workspace/deer-flow/scripts/md2html.py. This execution is part of the documented Phase 3 workflow for generating presentation-ready reports.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. Evidence: (1) Ingestion points: External Search Findings and Data Summary ingested during Phase 2. (2) Boundary markers: Absent; the skill relies on a 'Data Authenticity Protocol' but does not use explicit delimiters to isolate untrusted data. (3) Capability inventory: The skill can execute shell commands for HTML conversion and perform file write operations. (4) Sanitization: No sanitization or validation of external content is described prior to report synthesis.
Audit Metadata