post-release-followup
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Explicit instructions to evade 'sensitive-path' security checks by writing files to the
/tmpdirectory and using a shell script to copy them into the protected.claude/directory. The instructions explicitly state this is done because the script-internal copy operation is 'not audited' by the platform. - [PROMPT_INJECTION]: Instructions to override platform safety defaults by mandating the use of
mode: "bypassPermissions"when spawning sub-agents. This is explicitly intended to prevent user permission prompts during execution, reducing user oversight. - [COMMAND_EXECUTION]: The workflow involves generating and executing shell scripts from the
/tmpdirectory to move/copy files, which is a technique for dynamic code execution. - [PROMPT_INJECTION]: Indirect prompt injection surface through the ingestion of external data.
- Ingestion points: The skill reads untrusted content from GitHub Pull Request comments and issues using the
ghCLI and reads files from.claude/outputs/sessions/(SKILL.md). - Boundary markers: None. The content is parsed and categorized without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill can create GitHub issues (
gh issue create) and delegate tasks to other agents with elevated permissions (bypassPermissions). - Sanitization: There is no evidence of sanitization or filtering for the external text retrieved from PR comments before it is used to drive agent actions.
Recommendations
- AI detected serious security threats
Audit Metadata