token-waste

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session logs (.jsonl files) which contain untrusted data from previous conversations. If these logs contain malicious instructions disguised as redundant or confusing content, they could influence the automated system modifications.
  • Ingestion points: SKILL.md (Step 2) uses find to locate and read session logs in ~/.claude/projects and ~/.pi/agent/sessions.
  • Boundary markers: No boundary markers or 'ignore instructions' directives are present in the prompts for the waste-analyst or waste-adapter agents.
  • Capability inventory: The waste-adapter agent possesses Edit and Write tools to modify ~/AGENTS.md, ~/.claude/agents/, and skill body files. SKILL.md also executes Bash and Task commands.
  • Sanitization: The lib/detect_waste.py script provides excerpts of large content, but the waste-analyst and waste-adapter subagents act on this data to determine and execute system modifications without further validation.
  • [COMMAND_EXECUTION]: SKILL.md performs extensive operations via Bash, including searching sensitive directories (find), executing external scripts (python), and managing files in /tmp.
  • [PERSISTENCE]: The waste-adapter agent is explicitly designed to modify core agent configuration files, including global behavioral rules in ~/AGENTS.md and agent definitions in ~/.claude/agents/. While intended for optimization, this capability allows for persistent modification of the agent's long-term behavior.
  • [DATA_EXFILTRATION]: The skill accesses sensitive file paths that store the agent's operational history and project data (~/.claude/projects and ~/.pi/agent/sessions). These logs contain full conversation transcripts which may include sensitive information or credentials inadvertently shared in prior sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — token-waste