phoenixclaw-ledger

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts financial data from potentially untrusted sources such as natural language chat history and payment screenshots.\n
  • Ingestion points: Text-based 'moments' from conversations and OCR-extracted data from payment app screenshots.\n
  • Boundary markers: The provided templates in the assets/ directory do not utilize boundary markers or explicit instructions to the model to ignore potential injection attempts within the transaction data.\n
  • Capability inventory: The skill has the capability to read and write local files (YAML and Markdown) within the user's home directory and can schedule tasks using the openclaw cron command.\n
  • Sanitization: There are no documented validation or sanitization routines for extracted merchant names or descriptions before they are persisted in structured data files or rendered in reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 11:32 PM
Security Audit — agent-trust-hub — phoenixclaw-ledger