pipeline

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive shell operations using the Bash tool, including git management, GitHub CLI interactions (gh issue, gh label, gh api), and the execution of multiple repository-local scripts such as .github/scripts/verify-template-sync.sh and scripts/verify-version-sync.sh. It also implements a persistence mechanism by writing state files to the /tmp directory (e.g., /tmp/.claude-pipeline-{name}-{PPID}.json) to allow resuming potentially dangerous operations across multiple interactions.
  • [PROMPT_INJECTION]: The skill contains instructions to override standard agent behavior and is vulnerable to indirect injection from external data sources.
  • Permission Bypass: The instructions explicitly direct the agent to use mode: "bypassPermissions" when calling the Agent tool. This is intended to suppress user confirmation prompts for file edits and command executions, effectively escalating the agent's autonomy and reducing human oversight.
  • Indirect Injection: The workflow ingests untrusted data from GitHub issue bodies via gh issue list. This content is used to determine the scope of work and drive the logic of sub-agents during the implementation phase.
  • Ingestion points: workflows/auto-dev.yaml (pre-triage step).
  • Boundary markers: Absent.
  • Capability inventory: The implement step uses the Agent tool to perform writes, commits, and script executions.
  • Sanitization: No validation or escaping of ingested issue body content is performed before it influences downstream agent behavior.
  • [DATA_EXFILTRATION]: The instructions specifically target the .claude/ directory for direct write and edit operations. This directory is a sensitive location containing agent configuration and skill definitions; unauthorized modifications to these files can lead to persistent compromise of agent behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — pipeline