phoenixclaw-ledger
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill extracts financial data from potentially untrusted sources such as natural language chat history and payment screenshots.\n
- Ingestion points: Text-based 'moments' from conversations and OCR-extracted data from payment app screenshots.\n
- Boundary markers: The provided templates in the
assets/directory do not utilize boundary markers or explicit instructions to the model to ignore potential injection attempts within the transaction data.\n - Capability inventory: The skill has the capability to read and write local files (YAML and Markdown) within the user's home directory and can schedule tasks using the
openclaw croncommand.\n - Sanitization: There are no documented validation or sanitization routines for extracted merchant names or descriptions before they are persisted in structured data files or rendered in reports.
Audit Metadata