result-aggregation
Fail
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions explicitly reference a
mode: "bypassPermissions"configuration, which is intended to circumvent standard security constraints. - The documentation encourages agents to write directly to the
.claude/directory (e.g.,.claude/outputs/sessions/), which is a sensitive path containing application metadata and configuration. - It references internal protocols (R006, R010, #1101) to justify these escalated privileges, potentially leading the agent to ignore standard file system safety boundaries.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to aggregate data from external agent outputs, which represents an unvalidated data ingestion surface.
- Ingestion points: Files located at
.claude/outputs/sessions/{date}/{skill}-{HHmmss}.md. - Boundary markers: The provided aggregation templates (Standard, Detailed, Error formats) do not include delimiters or instructions to treat sub-agent summaries as untrusted data.
- Capability inventory: The skill instructs the agent to use the 'Read' tool to fetch external content and then process it into a final summary.
- Sanitization: There is no evidence of escaping, filtering, or validation logic to ensure that malicious instructions within sub-agent results do not influence the behavior of the aggregator agent.
- [DATA_EXPOSURE]: The skill facilitates the reading and potential consolidation of multiple session artifacts into a single output. If sub-agents have access to sensitive information, this aggregation pattern could expose that data in a simplified format without proper access control checks on the source files.
Recommendations
- AI detected serious security threats
Audit Metadata