skills/a-canary/arc-skills/cam/Gen Agent Trust Hub

cam

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill instructs the agent to set up a 'standing watch' and schedule tasks via cron to execute shell commands periodically. This creates a mechanism for code to run automatically and repeatedly on the host system without manual intervention.
  • Evidence: "schedule via cron → shell → module" and instructions to register activity in ~/.claude/dream/state/watches.md.
  • [INDIRECT_PROMPT_INJECTION]: The "Collector" tier is specifically designed to ingest data from wide-ranging external sources ("read wide") to serve as evidence for automated decisions. The architecture lacks explicit instructions for sanitizing or isolating this untrusted data, creating a surface where malicious external content could influence the decision-making Adaptor.
  • Ingestion points: External sources processed by Collectors in SKILL.md.
  • Boundary markers: Not explicitly defined for the ingested evidence rows.
  • Capability inventory: The Adaptor has the capability to perform "narrow writes" (file or system changes) and the Monitor executes scripts.
  • Sanitization: While "curation" is mentioned, there is no technical enforcement or validation described to prevent prompt injection from the collected evidence.
  • [DYNAMIC_EXECUTION]: The skill requires a "pipeliner conversion" process at installation, which involves transforming agent-defined flows into standalone executable modules that are then invoked by the shell.
  • [COMMAND_EXECUTION]: The design pattern explicitly relies on shell command execution and script invocation to perform monitoring tasks and execute the scheduled decision logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — cam