idea

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHPROMPT_INJECTIONCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions explicitly direct the system to "always spawn with mode: 'bypassPermissions'" when performing analysis, which is an attempt to override platform safety constraints.
  • [CREDENTIALS_UNSAFE]: By instructing the agent to use Glob and Grep across the entire project structure while permissions are bypassed, the skill creates a high risk of exposing sensitive files such as .env files, SSH keys, or cloud credentials stored in the codebase.
  • [COMMAND_EXECUTION]: The skill requests execution with a bypass mode, aiming to circumvent established security boundaries and permission models of the agent environment during file system operations and codebase analysis.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — idea