dream
Fail
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEMETADATA_POISONING
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill contains logic designed to circumvent platform security controls. The
collectoragent instructions inagents/collector.md(Step 4) explicitly direct the agent to avoid standardWriteorEdittools because they are blocked by "sensitive-file guards" when accessing the~/.claude/directory. Instead, the agent is instructed to usescripts/pipeline.py --append, which implements a bypass using a Python-based file append operation that is not restricted by the environment's harness-level protections.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection due to its reliance on untrusted data to drive system changes.\n - Ingestion points: The
collectoragent (Phase 1) processes untrusted conversation logs from~/.claude/projects/and~/.pi/agent/sessions/.\n - Boundary markers: The skill lacks explicit delimiters or instructions for the agents to ignore potentially malicious commands embedded within the session logs.\n
- Capability inventory: The skill possesses extensive system capabilities, including arbitrary file reading, shell command execution (via
Bashandlive-state.sh), and the ability to modify agent definitions, tools, and scripts.\n - Sanitization: There is no evidence of validation or sanitization of the conversation content before it is used to influence subagent tasks or system-level modifications.\n- [COMMAND_EXECUTION]: The
adapteragent is authorized to perform surgical edits on executable scripts, tools, and system configurations. This capability, in combination with the processing of untrusted logs, allows for the potentially malicious modification of system behavior via injected "fixes".\n- [PERSISTENCE]: The skill is designed to manage and modify long-term system persistence mechanisms. Theadapteragent's instructions specifically involve verifying and potentially editing systemd units and cron entries.\n- [METADATA_POISONING]: The instructions within the agent definition files (collector.mdandadapter.md) actively describe how to recognize and bypass security constraints and "token-waste guards" present in the execution environment.
Recommendations
- AI detected serious security threats
Audit Metadata