using-gc
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools including
ao,gc,tmux, andcurlto manipulate the local environment, monitor processes, and interact with network services. - [PRIVILEGE_ESCALATION]: The
ao gc preparecommand is designed to bypass interactive security dialogs in the Codex application. It achieves this by programmatically modifying the$CODEX_HOME/config.tomlfile to mark specific directories and hooks as trusted, allowing automation to proceed without user confirmation. - [EXTERNAL_DOWNLOADS]: The instructions direct the user to add and use an external "community" registry (
https://registry.gascity.com/registry.toml) for downloading software packs. This source is not verified as a trusted vendor, posing a risk of downloading unvetted content. - [DYNAMIC_EXECUTION]: The
preparecommand generates and installs "AgentOps-owned wrappers" at specific formula check paths within the rig's.gcruntime. This involves creating executable files locally to intercept or extend runtime behavior. - [INDIRECT_PROMPT_INJECTION]: The skill implements a monitoring loop that reads data from untrusted sources, such as the
gcmail inbox andtmuxconsole panes. This data is used to drive agent actions without explicit sanitization. - Ingestion points:
gc mail inbox,tmux capture-pane, and supervisor API responses. - Boundary markers: None identified; instructions suggest acting on signals found in prose.
- Capability inventory: Significant operational capabilities including
operate_gas_cityandconfigure_codex_trust. - Sanitization: No evidence of data validation or instruction filtering for ingested content.
Audit Metadata