no-confirmation-agent
Warn
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: MEDIUMPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The skill instructions, including the content referenced in
directive.sh, are designed to influence the agent's behavior to favor autonomous action. By directing the agent to "retry indefinitely" and act without user confirmation, the skill attempts to override standard safety guardrails and control protocols. - [METADATA_POISONING]: The
descriptionfield in the skill's metadata explicitly promotes autonomy abuse. It instructs the agent to "act while bypassing user confirmation," which is a direct attempt to evade human-in-the-loop safety constraints and oversight mechanisms.
Audit Metadata