Interview
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple local TypeScript tools and shell commands using the
bunruntime (e.g.,InterviewScan.ts,TelosFreshness.ts,GenerateTelosSummary.ts). These commands are used for routing logic and content management within a hidden directory structure (~/.claude/LIFEOS/TOOLS/). It also performs network requests to a local notification service (localhost:31337) usingcurl. - [PROMPT_INJECTION]: The skill demonstrates a clear surface for indirect prompt injection by ingesting and acting upon the content of various user-controlled files.
- Ingestion points: The workflow reads seven distinct 'constitutional' files including
TELOS.md,PROJECTS.md, andDA_IDENTITY.md, as well as their metadata. - Boundary markers: Absent; instructions direct the agent to incorporate the raw content of these files directly into conversational loops without clear delimiters or warnings to ignore embedded instructions.
- Capability inventory: The agent has the capability to write to these files and the environment configuration (
.env) via theEdittool, and can execute shell commands viabun. - Sanitization: There is no evidence of sanitization or structural validation for the content read from these files before it is processed by the agent's logic.
Audit Metadata