autonomous-loops
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: Security-conscious documentation and best practices. The skill includes explicit warnings against piping external scripts directly to the shell (curl | bash) and demonstrates how to implement the principle of least privilege by using the --allowedTools flag to restrict agent capabilities during specific loop phases.
- [PROMPT_INJECTION]: Indirect Prompt Injection surface analysis.
- Ingestion points: The loop architectures (Infinite Agentic Loop, Continuous Claude, and Ralphinho) ingest untrusted data from external specification markdown files, RFC documents, and pull request content.
- Boundary markers: The skill utilizes isolated context windows via separate 'claude -p' calls as a structural boundary to prevent context bleed across workflow steps, though it does not explicitly mention data-level delimiters.
- Capability inventory: The orchestrated loops possess capabilities for shell command execution (Bash), filesystem modification (Write, Edit), and repository management (GitHub CLI).
- Sanitization: The documentation does not describe specific sanitization, validation, or escaping protocols for the processed markdown or RFC content before it is interpolated into agent prompts.
Audit Metadata