token-waste
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes session logs (
.jsonlfiles) which contain untrusted data from previous conversations. If these logs contain malicious instructions disguised as redundant or confusing content, they could influence the automated system modifications. - Ingestion points:
SKILL.md(Step 2) usesfindto locate and read session logs in~/.claude/projectsand~/.pi/agent/sessions. - Boundary markers: No boundary markers or 'ignore instructions' directives are present in the prompts for the
waste-analystorwaste-adapteragents. - Capability inventory: The
waste-adapteragent possessesEditandWritetools to modify~/AGENTS.md,~/.claude/agents/, and skill body files.SKILL.mdalso executesBashandTaskcommands. - Sanitization: The
lib/detect_waste.pyscript provides excerpts of large content, but thewaste-analystandwaste-adaptersubagents act on this data to determine and execute system modifications without further validation. - [COMMAND_EXECUTION]:
SKILL.mdperforms extensive operations viaBash, including searching sensitive directories (find), executing external scripts (python), and managing files in/tmp. - [PERSISTENCE]: The
waste-adapteragent is explicitly designed to modify core agent configuration files, including global behavioral rules in~/AGENTS.mdand agent definitions in~/.claude/agents/. While intended for optimization, this capability allows for persistent modification of the agent's long-term behavior. - [DATA_EXFILTRATION]: The skill accesses sensitive file paths that store the agent's operational history and project data (
~/.claude/projectsand~/.pi/agent/sessions). These logs contain full conversation transcripts which may include sensitive information or credentials inadvertently shared in prior sessions.
Audit Metadata