openclaw-helper

Pass

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is explicitly designed to execute commands using the openclaw CLI tool, such as openclaw doctor, openclaw logs, and openclaw config set, to diagnose and fix system issues.
  • [DATA_EXFILTRATION]: The skill enables the agent to read system configurations and logs via openclaw config get and openclaw logs, which may contain sensitive data, API keys, or credentials stored within the tool's environment.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is instructed to follow instructions from documentation and troubleshooting logs.
  • Ingestion points: Documentation files listed in references/docs-index.md and troubleshooting history in references/experience.md.
  • Boundary markers: Absent; the skill lacks specific markers or instructions to treat documentation content as untrusted or to ignore embedded commands.
  • Capability inventory: The agent has control over the OpenClaw environment through the CLI, including state inspection and configuration modification.
  • Sanitization: Absent; the skill does not perform any validation or filtering of content from the documentation files before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 9, 2026, 09:58 AM