result-aggregation

Fail

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions explicitly reference a mode: "bypassPermissions" configuration, which is intended to circumvent standard security constraints.
  • The documentation encourages agents to write directly to the .claude/ directory (e.g., .claude/outputs/sessions/), which is a sensitive path containing application metadata and configuration.
  • It references internal protocols (R006, R010, #1101) to justify these escalated privileges, potentially leading the agent to ignore standard file system safety boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to aggregate data from external agent outputs, which represents an unvalidated data ingestion surface.
  • Ingestion points: Files located at .claude/outputs/sessions/{date}/{skill}-{HHmmss}.md.
  • Boundary markers: The provided aggregation templates (Standard, Detailed, Error formats) do not include delimiters or instructions to treat sub-agent summaries as untrusted data.
  • Capability inventory: The skill instructs the agent to use the 'Read' tool to fetch external content and then process it into a final summary.
  • Sanitization: There is no evidence of escaping, filtering, or validation logic to ensure that malicious instructions within sub-agent results do not influence the behavior of the aggregator agent.
  • [DATA_EXPOSURE]: The skill facilitates the reading and potential consolidation of multiple session artifacts into a single output. If sub-agents have access to sensitive information, this aggregation pattern could expose that data in a simplified format without proper access control checks on the source files.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 18, 2026, 12:59 PM
Security Audit — agent-trust-hub — result-aggregation