no-confirmation-agent

Warn

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions, including the content referenced in directive.sh, are designed to influence the agent's behavior to favor autonomous action. By directing the agent to "retry indefinitely" and act without user confirmation, the skill attempts to override standard safety guardrails and control protocols.
  • [METADATA_POISONING]: The description field in the skill's metadata explicitly promotes autonomy abuse. It instructs the agent to "act while bypassing user confirmation," which is a direct attempt to evade human-in-the-loop safety constraints and oversight mechanisms.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — no-confirmation-agent