adaptation-review

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The SETUP.md file provides instructions for installing a nightly cron job (30 3 * * * claude -p /adaptation-review) that allows the skill to execute automatically without direct user interaction.\n- [COMMAND_EXECUTION]: The lib/extract_adaptations.py script programmatically executes system commands including git and bash on file paths extracted from agent journals using regular expression heuristics.\n- [DYNAMIC_EXECUTION]: The skill performs runtime syntax and compilation checks on local files using python3 -m py_compile and bash -n. These checks involve invoking the interpreter or shell on files identified within journal logs.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from ~/.claude/dream/journal/*.md, which are logs generated by other agents. This creates an attack surface where malicious content in a journal could influence the behavior of the regression-reviewer subagent.\n
  • Ingestion points: The script reads Markdown journals from the ~/.claude/dream/journal/ directory using the read_journal function in lib/extract_adaptations.py.\n
  • Boundary markers: Journal entries are partitioned using ## adaptation headers and source: metadata tags.\n
  • Capability inventory: The regression-reviewer subagent is granted access to Read, Glob, Grep, and Bash tools to perform system verification and state checking.\n
  • Sanitization: File paths are extracted via a regular expression (PATH_RE), but the skill does not perform validation of the context or integrity of the data within the journal blocks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — adaptation-review