objective-counsel-approval
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bun -eto execute JavaScript code for querying the~/vault/ledger.dbSQLite database. Executing logic via shell-based string arguments is a high-privilege pattern. - Evidence:
PATH=$HOME/.bun/bin:$PATH bun -e '…bun:sqlite…'is used to perform throttle checks and database operations. - [DYNAMIC_EXECUTION]: The skill provides JavaScript snippets to be interpreted and executed at runtime by the Bun environment to facilitate database interactions.
- Evidence: Detailed logic for querying and normalizing the
created_atfield is passed directly to the Bun runtime via the-eflag. - [PERSISTENCE]: The instructions explicitly direct the establishment of a persistent execution mechanism using a system cron job.
- Evidence: Section 5 states "Cron the hourly tick via
claude -p" with a recommended*/60cadence to maintain adjudication activity. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from "PRD-body proposals" and "CHOICES fence rows" which are authored by other agent components and could contain malicious instructions.
- Ingestion points: Processes objectives embedded in
PRD-body proposalsandCHOICES fence rowsinSKILL.md. - Boundary markers: None explicitly mentioned; the skill relies on an internal heuristic-based "gate-class check" to identify sensitive actions.
- Capability inventory: Accesses sensitive local files (
~/vault/missions.md,~/vault/ledger.db), executes shell commands (bun -e), and writes to the feedback ledger. - Sanitization: Implements a conservative classification check to route high-risk actions (spending, publishing, credential changes) to a human gate.
Audit Metadata