skills/a-canary/arc-skills/dream/Gen Agent Trust Hub

dream

Fail

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEMETADATA_POISONING
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill contains logic designed to circumvent platform security controls. The collector agent instructions in agents/collector.md (Step 4) explicitly direct the agent to avoid standard Write or Edit tools because they are blocked by "sensitive-file guards" when accessing the ~/.claude/ directory. Instead, the agent is instructed to use scripts/pipeline.py --append, which implements a bypass using a Python-based file append operation that is not restricted by the environment's harness-level protections.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection due to its reliance on untrusted data to drive system changes.\n
  • Ingestion points: The collector agent (Phase 1) processes untrusted conversation logs from ~/.claude/projects/ and ~/.pi/agent/sessions/.\n
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agents to ignore potentially malicious commands embedded within the session logs.\n
  • Capability inventory: The skill possesses extensive system capabilities, including arbitrary file reading, shell command execution (via Bash and live-state.sh), and the ability to modify agent definitions, tools, and scripts.\n
  • Sanitization: There is no evidence of validation or sanitization of the conversation content before it is used to influence subagent tasks or system-level modifications.\n- [COMMAND_EXECUTION]: The adapter agent is authorized to perform surgical edits on executable scripts, tools, and system configurations. This capability, in combination with the processing of untrusted logs, allows for the potentially malicious modification of system behavior via injected "fixes".\n- [PERSISTENCE]: The skill is designed to manage and modify long-term system persistence mechanisms. The adapter agent's instructions specifically involve verifying and potentially editing systemd units and cron entries.\n- [METADATA_POISONING]: The instructions within the agent definition files (collector.md and adapter.md) actively describe how to recognize and bypass security constraints and "token-waste guards" present in the execution environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — dream