sandbox-guard

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The generated Dockerfiles reference the node:20-alpine image from Docker Hub, which is a well-known and standard base image.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided skill names and permission sets to generate configuration files.\n
  • Ingestion points: Input placeholders like <name> and permission lists are used to populate Dockerfiles and shell commands.\n
  • Boundary markers: The skill does not define specific delimiters for these inputs to prevent potential code or command injection into the generated output.\n
  • Capability inventory: The skill has file-write access to save results to the .openclaw/sandbox/ directory.\n
  • Sanitization: No specific sanitization or escaping of the user-provided input is defined before its inclusion in the generated output. However, the skill mandates a human review step (Rule 9) before any files are written to disk, which significantly mitigates this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:44 AM
Security Audit — agent-trust-hub — sandbox-guard