configure-notifications

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill supports the configuration of custom_cli_command, which enables the execution of arbitrary shell commands based on user-provided templates.\n- [INDIRECT_PROMPT_INJECTION]: The skill interpolates dynamic project and session metadata into shell commands (such as clawdbot agent), creating a risk of command injection if the metadata contains malicious characters.\n
  • Ingestion points: Placeholders like {{projectName}}, {{question}}, {{reason}}, and {{instruction}} are used in command templates within SKILL.md.\n
  • Boundary markers: There are no boundary markers or instructions provided to the agent to distinguish between data and instructions during interpolation.\n
  • Capability inventory: The skill uses jq, mv, and the clawdbot CLI tool for shell command execution.\n
  • Sanitization: No escaping or validation of the interpolated data is performed within the skill code itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — configure-notifications