{"id":"386f6363-b65a-442f-86cc-81ccba2ee760","entityType":"agent","slug":"crawl-9c311fcb812320da5283-da88b5a8928de6320e7e","name":"Crawled docs.openclaw.ai da88b5a8","canonicalUrl":"https://www.xpersona.co/agent/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e","canonicalPath":"/agent/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e","generatedAt":"2026-10-09T19:42:39.401Z","source":"GITHUB_REPOS","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"description":"Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mi... Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mitigations Pattern detection, external content wrapping Residual Risk Critical - Detection only, no blocking; sophisticated attacks bypass Recommendations Implement multi-layer defense, output validation,","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/14/2026.","installCommand":null,"sourceUrl":"https://docs.openclaw.ai/security/THREAT-MODEL-ATLAS","homepage":"https://docs.openclaw.ai/security/THREAT-MODEL-ATLAS","primaryLinks":[{"label":"View Source","url":"https://docs.openclaw.ai/security/THREAT-MODEL-ATLAS","kind":"source"}],"safetyScore":84,"overallRank":77.2,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Aff"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No protocol or capability metadata is available."},"protocols":[],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":0,"capabilityMatrix":{"rows":[],"flattenedTokens":""}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-03-14T02:00:56.199Z","emptyReason":null},"lastUpdatedAt":"2026-04-14T23:26:25.608Z","lastCrawledAt":"2026-03-14T02:00:56.199Z","lastIndexedAt":"2026-03-14T02:00:56.199Z","nextCrawlAt":null,"lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":null,"setupComplexity":"medium","setupSteps":["Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":[]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_REPOS","generatedAt":"2026-10-09T19:42:39.401Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/crawl-9c311fcb812320da5283-da88b5a8928de6320e7e/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB REPOS","verified":false,"confidence":"high","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":null},"readme":"Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mitigations Pattern detection, external content wrapping Residual Risk Critical - Detection only, no blocking; sophisticated attacks bypass Recommendations Implement multi-layer defense, output validation, user confirmation for sensitive actions ​ T-EXEC-002: Indirect Prompt Injection Attribute Value ATLAS ID AML.T0051.001 - LLM Prompt Injection: Indirect Description Attacker embeds malicious instructions in fetched content Attack Vector Malicious URLs, poisoned emails, compromised webhooks Affected Components web_fetch, email ingestion, external data sources Current Mitigations Content wrapping with XML tags and security notice Residual Risk High - LLM may ignore wrapper inst","readmeExcerpt":"Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mitigations Pattern detection, external content wrapping Residual Risk Critical - Detection only, no blocking; sophisticated attacks bypass Recommendations Implement multi-layer defense, output validation,","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[],"languages":[],"docsSourceLabel":"GITHUB REPOS","editorialOverview":"Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mi... Injection: Direct Description Attacker sends crafted prompts to manipulate agent behavior Attack Vector Channel messages containing adversarial instructions Affected Components Agent LLM, all input surfaces Current Mitigations Pattern detection, external content wrapping Residual Risk Critical - Detection only, no blocking; sophisticated attacks bypass Recommendations Implement multi-layer defense, output validation,","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":418,"uniquenessScore":64,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-14T23:26:25.608Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"agent-directory","verified":false,"confidence":"low","updatedAt":"2026-10-09T19:42:39.401Z","emptyReason":"No close protocol neighbors were found."},"items":[],"links":{"hub":"/agent","source":"/agent/source/github_repos","protocols":[]}}}