skillopt-lite
Fail
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The
minefunction inskillopt.tsprogrammatically scans and reads conversation transcripts from the~/.claude/projectsdirectory. This location contains sensitive history of user interactions with the AI agent. The skill allows overriding the LLM endpoint via the--baseflag, which creates a path for this sensitive data to be transmitted to external servers. - [COMMAND_EXECUTION]: The
rolloutfunction utilizesBun.spawnSyncto execute shell commands, specifically invoking a Docker-based sandbox script (run.sh) and thechmodutility on the host machine. - [PRIVILEGE_ESCALATION]: The
rolloutfunction executeschmod -R a+rwXon temporary directories. This grants overly broad read, write, and execute permissions to all users on the system for those files, violating the principle of least privilege. - [INDIRECT_PROMPT_INJECTION]: The skill processes historical conversation transcripts, which constitute untrusted data that could contain malicious instructions designed to influence the behavior of the agent during the optimization loop.
- Ingestion points: Transcript data is read from
.jsonlfiles in~/.claude/projectsby themine()function. - Boundary markers: No delimiters or isolation instructions are present to prevent the agent from treating transcript content as authoritative commands.
- Capability inventory: The skill has access to
Bash,Write, andEdittools, and the supporting script usesBun.spawnSyncfor system-level execution. - Sanitization: The content is truncated but otherwise processed without validation or escaping.
Recommendations
- AI detected serious security threats
Audit Metadata