pipeline
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive shell operations using the
Bashtool, including git management, GitHub CLI interactions (gh issue,gh label,gh api), and the execution of multiple repository-local scripts such as.github/scripts/verify-template-sync.shandscripts/verify-version-sync.sh. It also implements a persistence mechanism by writing state files to the/tmpdirectory (e.g.,/tmp/.claude-pipeline-{name}-{PPID}.json) to allow resuming potentially dangerous operations across multiple interactions. - [PROMPT_INJECTION]: The skill contains instructions to override standard agent behavior and is vulnerable to indirect injection from external data sources.
- Permission Bypass: The instructions explicitly direct the agent to use
mode: "bypassPermissions"when calling the Agent tool. This is intended to suppress user confirmation prompts for file edits and command executions, effectively escalating the agent's autonomy and reducing human oversight. - Indirect Injection: The workflow ingests untrusted data from GitHub issue bodies via
gh issue list. This content is used to determine the scope of work and drive the logic of sub-agents during the implementation phase. - Ingestion points:
workflows/auto-dev.yaml(pre-triage step). - Boundary markers: Absent.
- Capability inventory: The
implementstep uses theAgenttool to perform writes, commits, and script executions. - Sanitization: No validation or escaping of ingested issue body content is performed before it influences downstream agent behavior.
- [DATA_EXFILTRATION]: The instructions specifically target the
.claude/directory for direct write and edit operations. This directory is a sensitive location containing agent configuration and skill definitions; unauthorized modifications to these files can lead to persistent compromise of agent behavior.
Recommendations
- AI detected serious security threats
Audit Metadata