skills/5dive-ai/skills/find-loops/Gen Agent Trust Hub

find-loops

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes shell commands using the npx agenticloops and 5dive loop CLI tools to search for, validate, and manage recurring agents.
  • [PERSISTENCE]: The skill's primary function is to register recurring, scheduled tasks (loops) on the host system using cron-style triggers (e.g., 5dive loop install ... --cron="..."). This establishes persistence for automated agent runs.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation and execution of external 'loops' from a remote directory. These loops contain executable skills and prompts that are run by the agent harness.
  • [EXTERNAL_DOWNLOADS]: Fetches agent metadata and installation files from vendor-associated sources, specifically agenticloops.dev and the 5dive-ai/loops GitHub repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect injection by processing data from an external directory of agents.
  • Ingestion points: Data ingested from npx agenticloops find results, which include author-provided descriptions and loop names.
  • Boundary markers: The instructions do not specify formal delimiters for external data but provide explicit vetting steps for the agent to perform.
  • Capability inventory: The agent has capabilities for command execution, task scheduling, and remote package installation.
  • Sanitization: The skill mitigates risks by instructing the agent to vet the requires block (identifying requested CLI tools, secrets, and network egress) and to check source reputation before recommending installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 03:58 PM
Security Audit — agent-trust-hub — find-loops