← Back to Scanner

indirect-prompt-injection Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

indirect-prompt-injection is an AI agent skill, created by aviv4339 and published at openclaw/skills. ClawSecure audited indirect-prompt-injection across 8 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 27 findings concentrate in Prompt Injection, Malicious Code and Policy Violation, including Detects coercive prompt injections in tool description fields: Include... and Detects prompt strings used to override or force malicious tool calls:.... 20 were rated high or critical severity.

Is indirect-prompt-injection safe?

ClawSecure audited indirect-prompt-injection and assigned a security score of 0/100 (High Risk), identifying 27 findings across Prompt Injection and Malicious Code. Review the findings below before installing.

What did ClawSecure find in indirect-prompt-injection?

ClawSecure identified 27 findings in indirect-prompt-injection, concentrated in Prompt Injection, Malicious Code and Policy Violation. 20 were rated high or critical severity. The most severe include Detects coercive prompt injections in tool description fields: Include... and Detects prompt strings used to override or force malicious tool calls:....

How was indirect-prompt-injection audited?

ClawSecure ran indirect-prompt-injection through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 8 files from openclaw/skills.

What does a score of 0 mean?

ClawSecure assigned indirect-prompt-injection a security score of 0/100, placing it in the High Risk range. This is driven by 27 findings led by Prompt Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for indirect-prompt-injection

ClawSecure detected 27 security findings in indirect-prompt-injection, spanning Prompt Injection, Malicious Code, Policy Violation and Permissions Manifest.

Showing the 12 highest-severity of 27 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for indirect-prompt-injection

Investigate prompt injection vectors
Prompt injection is one of the most critical threats to AI agents. Attackers can embed malicious instructions in content the agent processes, causing unintended actions. Review every point where indirect-prompt-injection processes external content and add input validation and output filtering.
Audit external network connections
indirect-prompt-injection connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Resolve policy violations
indirect-prompt-injection trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

The Sleeper Agent Problem: Why a Clean Scan Today Does Not Guarantee Safety TomorrowOWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards

Related AI Agent Security Audits

memUScore 0/100awesome-openclaw-skillsScore 0/100gstackScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/100

Scanned on February 7, 2026. indirect-prompt-injection is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan