Interview

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple local TypeScript tools and shell commands using the bun runtime (e.g., InterviewScan.ts, TelosFreshness.ts, GenerateTelosSummary.ts). These commands are used for routing logic and content management within a hidden directory structure (~/.claude/LIFEOS/TOOLS/). It also performs network requests to a local notification service (localhost:31337) using curl.
  • [PROMPT_INJECTION]: The skill demonstrates a clear surface for indirect prompt injection by ingesting and acting upon the content of various user-controlled files.
  • Ingestion points: The workflow reads seven distinct 'constitutional' files including TELOS.md, PROJECTS.md, and DA_IDENTITY.md, as well as their metadata.
  • Boundary markers: Absent; instructions direct the agent to incorporate the raw content of these files directly into conversational loops without clear delimiters or warnings to ignore embedded instructions.
  • Capability inventory: The agent has the capability to write to these files and the environment configuration (.env) via the Edit tool, and can execute shell commands via bun.
  • Sanitization: There is no evidence of sanitization or structural validation for the content read from these files before it is processed by the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 06:48 PM
Security Audit — agent-trust-hub — Interview