skills/wbunker/skills-repo/openwolf/Gen Agent Trust Hub

openwolf

Warn

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill installs Node.js scripts from the openwolf package into the .wolf/hooks/ directory and registers them in the agent configuration. These scripts execute on file lifecycle events, allowing external code to run with the agent's privileges.\n- [COMMAND_EXECUTION]: Utilizes commands to start background daemons and a local dashboard server, and includes a screenshot tool that runs a browser via puppeteer-core.\n- [EXTERNAL_DOWNLOADS]: Requires installing the openwolf and pm2 packages from public registries.\n- [PROMPT_INJECTION]: Automatically loads project-specific files like anatomy.md and cerebrum.md into the agent's prompt context at the start of every session, creating a vulnerability to indirect prompt injection from untrusted file content.\n- [DATA_EXFILTRATION]: The presence of a local dashboard on port 18791 and a network-capable browser engine for screenshots provides potential vectors for data exfiltration or exposure of workspace metadata.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 11:28 AM
Security Audit — agent-trust-hub — openwolf