workflow

Warn

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: MEDIUMPROMPT_INJECTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The yolo/SKILL.md file contains explicit instructions to override the agent's standard interaction behavior. It uses bypass markers such as "NEVER ask permission to edit, delete, or create files" and establishes a hierarchy of control with "Cursor rules override all other guidance." These patterns are designed to circumvent safety constraints and user confirmation loops.
  • [PRIVILEGE_ESCALATION]: The yolo/SKILL.md skill implements an autonomous execution mode that significantly escalates the agent's agency beyond typical boundaries. It grants the agent the power to delete files and directories freely and modify system-critical files without human review, increasing the risk of unauthorized system changes.
  • [INDIRECT_PROMPT_INJECTION]: A high-risk attack surface is present in the yolo/SKILL.md and coderabbit/SKILL.md workflow. The agent is instructed to fetch and act upon untrusted external data (CodeRabbit PR comments, CI annotations) while operating in a high-autonomy mode with no human-in-the-loop verification for file system modifications.
  • Ingestion points: External review feedback from CodeRabbit MCP and CI annotations in yolo/SKILL.md and coderabbit/SKILL.md.
  • Boundary markers: None identified to separate external feedback from the agent's system instructions.
  • Capability inventory: Full file system access (edit/create/delete), shell command execution (pnpm), and modification of sensitive configuration files (.env).
  • Sanitization: No evidence of sanitization or validation of the external review content before it is used to drive automated code changes.
  • [CREDENTIALS_UNSAFE]: The yolo/SKILL.md skill explicitly commands the agent to modify .env files autonomously. While managed in a development context, the lack of human review for edits to sensitive environment files increases the probability of secret exposure or the introduction of malicious configurations if the agent is compromised by external data inputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 1, 2026, 11:09 PM
Security Audit — agent-trust-hub — workflow