skills/openclaw/skills/self-xyz/Gen Agent Trust Hub

self-xyz

Pass

Audited by Gen Agent Trust Hub on Feb 14, 2026

Risk Level: LOWEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • SAFE (SAFE): The skill contains legitimate developer documentation for identity verification. No malicious patterns such as obfuscation, credential theft, or prompt injection were found. Identity attributes are handled via zero-knowledge proofs, which is a security best practice for privacy.\n- EXTERNAL_DOWNLOADS (LOW): The skill references the installation of @selfxyz/qrcode and @selfxyz/core packages via npm. These are standard libraries required for the protocol's functionality and do not originate from suspicious sources.\n- COMMAND_EXECUTION (INFO): Standard CLI instructions for package installation and local development (ngrok) are included. These are expected for a developer integration guide and do not pose a threat.\n- INDIRECT_PROMPT_INJECTION (LOW): The skill involves processing external data (identity proofs). However, the protocol's architecture uses cryptographic proofs as a boundary, and the verification library handles sanitization. The risk of injection affecting the agent's logic is negligible.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 14, 2026, 06:02 PM