objective-counsel-approval

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bun -e to execute JavaScript code for querying the ~/vault/ledger.db SQLite database. Executing logic via shell-based string arguments is a high-privilege pattern.
  • Evidence: PATH=$HOME/.bun/bin:$PATH bun -e '…bun:sqlite…' is used to perform throttle checks and database operations.
  • [DYNAMIC_EXECUTION]: The skill provides JavaScript snippets to be interpreted and executed at runtime by the Bun environment to facilitate database interactions.
  • Evidence: Detailed logic for querying and normalizing the created_at field is passed directly to the Bun runtime via the -e flag.
  • [PERSISTENCE]: The instructions explicitly direct the establishment of a persistent execution mechanism using a system cron job.
  • Evidence: Section 5 states "Cron the hourly tick via claude -p" with a recommended */60 cadence to maintain adjudication activity.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from "PRD-body proposals" and "CHOICES fence rows" which are authored by other agent components and could contain malicious instructions.
  • Ingestion points: Processes objectives embedded in PRD-body proposals and CHOICES fence rows in SKILL.md.
  • Boundary markers: None explicitly mentioned; the skill relies on an internal heuristic-based "gate-class check" to identify sensitive actions.
  • Capability inventory: Accesses sensitive local files (~/vault/missions.md, ~/vault/ledger.db), executes shell commands (bun -e), and writes to the feedback ledger.
  • Sanitization: Implements a conservative classification check to route high-risk actions (spending, publishing, credential changes) to a human gate.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — objective-counsel-approval