taste-review

Fail

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The bash script programmatically accesses the macOS Keychain using the security find-generic-password command to retrieve a secret OAuth token.- [COMMAND_EXECUTION]: The skill directs the agent to execute multiple shell commands, including system utilities for credential retrieval and the claude CLI for external processing.- [PROMPT_INJECTION]: The instructions explicitly guide the agent to 'Run outside the sandbox when required' and request 'reusable approval,' which are clear attempts to override the default security boundaries and sandbox constraints of the execution environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 8, 2026, 10:12 AM
Security Audit — agent-trust-hub — taste-review