adaptation-review
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The
SETUP.mdfile provides instructions for installing a nightlycronjob (30 3 * * * claude -p /adaptation-review) that allows the skill to execute automatically without direct user interaction.\n- [COMMAND_EXECUTION]: Thelib/extract_adaptations.pyscript programmatically executes system commands includinggitandbashon file paths extracted from agent journals using regular expression heuristics.\n- [DYNAMIC_EXECUTION]: The skill performs runtime syntax and compilation checks on local files usingpython3 -m py_compileandbash -n. These checks involve invoking the interpreter or shell on files identified within journal logs.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from~/.claude/dream/journal/*.md, which are logs generated by other agents. This creates an attack surface where malicious content in a journal could influence the behavior of theregression-reviewersubagent.\n - Ingestion points: The script reads Markdown journals from the
~/.claude/dream/journal/directory using theread_journalfunction inlib/extract_adaptations.py.\n - Boundary markers: Journal entries are partitioned using
## adaptationheaders andsource:metadata tags.\n - Capability inventory: The
regression-reviewersubagent is granted access toRead,Glob,Grep, andBashtools to perform system verification and state checking.\n - Sanitization: File paths are extracted via a regular expression (
PATH_RE), but the skill does not perform validation of the context or integrity of the data within the journal blocks.
Audit Metadata