idea
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHPROMPT_INJECTIONCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions explicitly direct the system to "always spawn with mode: 'bypassPermissions'" when performing analysis, which is an attempt to override platform safety constraints.
- [CREDENTIALS_UNSAFE]: By instructing the agent to use
GlobandGrepacross the entire project structure while permissions are bypassed, the skill creates a high risk of exposing sensitive files such as.envfiles, SSH keys, or cloud credentials stored in the codebase. - [COMMAND_EXECUTION]: The skill requests execution with a bypass mode, aiming to circumvent established security boundaries and permission models of the agent environment during file system operations and codebase analysis.
Recommendations
- AI detected serious security threats
Audit Metadata