cam
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill instructs the agent to set up a 'standing watch' and schedule tasks via
cronto execute shell commands periodically. This creates a mechanism for code to run automatically and repeatedly on the host system without manual intervention. - Evidence: "schedule via cron → shell → module" and instructions to register activity in
~/.claude/dream/state/watches.md. - [INDIRECT_PROMPT_INJECTION]: The "Collector" tier is specifically designed to ingest data from wide-ranging external sources ("read wide") to serve as evidence for automated decisions. The architecture lacks explicit instructions for sanitizing or isolating this untrusted data, creating a surface where malicious external content could influence the decision-making Adaptor.
- Ingestion points: External sources processed by Collectors in
SKILL.md. - Boundary markers: Not explicitly defined for the ingested evidence rows.
- Capability inventory: The Adaptor has the capability to perform "narrow writes" (file or system changes) and the Monitor executes scripts.
- Sanitization: While "curation" is mentioned, there is no technical enforcement or validation described to prevent prompt injection from the collected evidence.
- [DYNAMIC_EXECUTION]: The skill requires a "pipeliner conversion" process at installation, which involves transforming agent-defined flows into standalone executable modules that are then invoked by the shell.
- [COMMAND_EXECUTION]: The design pattern explicitly relies on shell command execution and script invocation to perform monitoring tasks and execute the scheduled decision logic.
Audit Metadata