skills/joelhooks/joelclaw/clawmail/Gen Agent Trust Hub

clawmail

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is centered around the use of the joelclaw mail command-line utility. It provides specific subcommands for agent coordination, such as send, inbox, read, reserve, and release. This is a standard functional requirement for the skill's intended purpose within the vendor's ecosystem.
  • [PROMPT_INJECTION]: The protocol creates a surface for indirect prompt injection because agents are instructed to read and act upon messages from external sources via joelclaw mail read.
  • Ingestion points: Incoming messages accessed through joelclaw mail read and joelclaw mail inbox (SKILL.md).
  • Boundary markers: The documentation does not specify the use of delimiters or 'ignore' instructions for the content of the messages.
  • Capability inventory: The agent has the capability to execute shell commands and modify files (referenced by mail reserve), which could be targeted by malicious instructions in a message.
  • Sanitization: No explicit sanitization or validation of the mail content is described in the protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 03:39 AM