RootCauseAnalysis

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands for local logging and event notification. These commands use curl to alert a local notification service at localhost:31337 and echo to append execution data to a local JSONL file at ~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl.
  • [SAFE]: The shell commands are limited to local operations and represent standard integration features for the author's specific environment. No remote scripts are downloaded or executed.
  • [DATA_EXFILTRATION]: Network activity is restricted to localhost, which is a whitelisted domain for local service communication. No sensitive data is transmitted to external servers.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data, such as incident reports and bug descriptions. While the skill interpolates summary text into local log entries without explicit sanitization, the restricted scope of the commands (local file system and localhost) prevents this from becoming a high-severity threat.
  • [DYNAMIC_EXECUTION]: The skill supports loading user-specific preferences and resources from a local path (~/.claude/LIFEOS/USER/CUSTOMIZATIONS/SKILLS/RootCauseAnalysis/). This allows for user-defined configuration and does not involve untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:47 AM
Security Audit — agent-trust-hub — RootCauseAnalysis