post-release-followup

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Explicit instructions to evade 'sensitive-path' security checks by writing files to the /tmp directory and using a shell script to copy them into the protected .claude/ directory. The instructions explicitly state this is done because the script-internal copy operation is 'not audited' by the platform.
  • [PROMPT_INJECTION]: Instructions to override platform safety defaults by mandating the use of mode: "bypassPermissions" when spawning sub-agents. This is explicitly intended to prevent user permission prompts during execution, reducing user oversight.
  • [COMMAND_EXECUTION]: The workflow involves generating and executing shell scripts from the /tmp directory to move/copy files, which is a technique for dynamic code execution.
  • [PROMPT_INJECTION]: Indirect prompt injection surface through the ingestion of external data.
  • Ingestion points: The skill reads untrusted content from GitHub Pull Request comments and issues using the gh CLI and reads files from .claude/outputs/sessions/ (SKILL.md).
  • Boundary markers: None. The content is parsed and categorized without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill can create GitHub issues (gh issue create) and delegate tasks to other agents with elevated permissions (bypassPermissions).
  • Sanitization: There is no evidence of sanitization or filtering for the external text retrieved from PR comments before it is used to drive agent actions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — post-release-followup