autoresearch
Fail
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override the agent's interactive safety protocols, directing it to operate autonomously and "never pause to ask permission" from the user during its operation.
- [COMMAND_EXECUTION]: The skill scaffolds and executes a bash script (
loop-driver.sh) that manages an automated sequence of tool uses and file modifications without human oversight or approval checkpoints. - [COMMAND_EXECUTION]: The generated
loop-driver.shscript utilizes the--permission-mode bypassPermissionsflag when invoking the agent. This configuration is a deliberate attempt to evade the platform's security framework and consent mechanisms, enabling the agent to perform sensitive file and system operations without prompting the user for consent.
Recommendations
- AI detected serious security threats
Audit Metadata