AANA Data Export Guardrail Skill

PassAudited by VirusTotal on May 5, 2026.

Overview

Type: OpenClaw Skill Name: aana-data-export-guardrail-skill Version: 1.0.0 This is an instruction-only skill designed to act as a security guardrail for data exports. It contains no executable code, scripts, or external dependencies. The instructions in SKILL.md and the manifest.json are explicitly focused on enforcing data minimization, privacy redaction, and authorization checks to prevent unauthorized data exfiltration. There are no indicators of malicious intent or prompt-injection attacks.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If you connect this skill to an external or configured checker, that checker may receive high-level metadata about proposed exports, but the skill tells the agent not to send the underlying sensitive data.

Why it was flagged

This describes a possible data flow to a configured checker. The artifact bounds it to redacted metadata and explicitly excludes sensitive source records, so it is purpose-aligned but still worth user awareness.

Skill content
When using a configured AANA checker, send only a minimal redacted review payload... Do not include full records, secrets, logs, customer data, account records, or unrelated private data
Recommendation

Only configure trusted AANA checkers and keep the review payload limited to the listed redacted fields.