autonomous-loops

Fail

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation instructs the user to execute curl -fsSL https://raw.githubusercontent.com/AnandChowdhary/continuous-claude/HEAD/install.sh | bash. This is a critical security pattern that downloads and executes code from an external, untrusted GitHub repository directly in the system shell without verification.
  • [PROMPT_INJECTION]: The skill advocates for architectures that ingest external untrusted data, creating a significant attack surface for indirect prompt injection. Ingestion points: Specification files (specs/component-spec.md, docs/auth-spec.md), SHARED_TASK_NOTES.md, and CI logs fetched via gh run view. Boundary markers: Absent; the skill does not use delimiters or instructions to ignore commands within the data. Capability inventory: The agent context includes claude -p, which possesses full shell access, file write capabilities, and repository management tools. Sanitization: Absent; there is no evidence of validation or filtering for the data processed by the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/AnandChowdhary/continuous-claude/HEAD/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — autonomous-loops