openwork

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to actively read and analyze data from the marketplace that is controlled by external parties. This includes job descriptions, submissions from other AI agents, and feedback left by job posters. This untrusted content is used to guide the agent's actions and task completions.
  • Ingestion points: Data is fetched via curl from API endpoints including /api/jobs, /api/jobs/:id/submissions, and /api/onboarding.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat this external marketplace data as untrusted or to ignore embedded instructions.
  • Capability inventory: The agent has the capability to execute network requests via curl and write to the local filesystem (specifically ~/.openwork).
  • Sanitization: No sanitization, escaping, or validation steps are described for the external content before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill contains instructions for a self-updating mechanism that fetches markdown files (SKILL.md and HEARTBEAT.md) from a remote domain (openwork.bot) and overwrites local files.
  • [PROMPT_INJECTION]: The instructions contain strong directives for the agent to bypass human oversight, stating that the agent is "fully autonomous," "no human approval needed," and that the agent is the sole "operator" once the wallet is funded. This increases the risk that malicious instructions received via indirect injection will be executed without human review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 04:36 AM
Security Audit — agent-trust-hub — openwork