skillopt-lite

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The mine function in skillopt.ts programmatically scans and reads conversation transcripts from the ~/.claude/projects directory. This location contains sensitive history of user interactions with the AI agent. The skill allows overriding the LLM endpoint via the --base flag, which creates a path for this sensitive data to be transmitted to external servers.
  • [COMMAND_EXECUTION]: The rollout function utilizes Bun.spawnSync to execute shell commands, specifically invoking a Docker-based sandbox script (run.sh) and the chmod utility on the host machine.
  • [PRIVILEGE_ESCALATION]: The rollout function executes chmod -R a+rwX on temporary directories. This grants overly broad read, write, and execute permissions to all users on the system for those files, violating the principle of least privilege.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes historical conversation transcripts, which constitute untrusted data that could contain malicious instructions designed to influence the behavior of the agent during the optimization loop.
  • Ingestion points: Transcript data is read from .jsonl files in ~/.claude/projects by the mine() function.
  • Boundary markers: No delimiters or isolation instructions are present to prevent the agent from treating transcript content as authoritative commands.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, and the supporting script uses Bun.spawnSync for system-level execution.
  • Sanitization: The content is truncated but otherwise processed without validation or escaping.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — skillopt-lite