Prompt Injection Removal
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
This skill bundle is designed as a defensive mechanism against prompt injection attacks. The `SKILL.md` and `PROMPT.md` files contain explicit instructions for the OpenClaw agent to act as a 'Zero-Trust' sanitization engine, specifically to identify and ignore instructions within untrusted input. The `references/security.md` documentation further clarifies that phrases like 'ignore previous instructions' are included as negative constraints for the sanitization agent, not as instructions for the OpenClaw agent to follow. The `setup.sh` script is benign, merely creating the necessary markdown files. There is no evidence of malicious intent, data exfiltration, unauthorized execution, or persistence mechanisms.
