automation-log

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides an optional command-line example for the openclaw platform to automate recurring health reports based on the recorded data.
  • [DATA_EXFILTRATION]: Includes an optional integration to send summarized health reports to a user-configured Telegram chat ID for remote monitoring.
  • [PROMPT_INJECTION]: Processes local markdown files (automation-log/automation-registry.md and automation-log/automations/*.md) to generate dashboards, which represents a surface for indirect prompt injection from workspace data; however, the risk is minimal as the content is user-controlled.
  • [CREDENTIALS_UNSAFE]: Implements a credential rotation tracking pattern that specifically instructs users to only list reference names and never store actual secrets in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 12:22 AM
Security Audit — agent-trust-hub — automation-log