ops-comms

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external communication channels, creating a surface for indirect prompt injection attacks where malicious instructions in incoming messages could influence the agent's behavior.
  • Ingestion points: WhatsApp messages (wacli), Gmail threads (gog), Slack messages (mcp__claude_ai_Slack), Telegram updates (mcp__claude_ops_telegram), and Notion pages/comments (mcp__claude_ai_Notion).
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions in the ingested content.
  • Capability inventory: Shell command execution (wacli, gog, curl, launchctl, bin/ops-discord), file read access (via Read tool and CLI outputs), and network transmission across all configured messaging channels.
  • Sanitization: Absent; the skill is instructed to summarize and address the content of the messages without explicit sanitization or filtering steps.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands and system utilities to perform its core functions.
  • Evidence: Uses wacli for WhatsApp operations, gog for Gmail/Calendar, telegram-cli as a fallback for Telegram, and curl for Notion API requests. It also uses launchctl to manage the wacli-keepalive daemon on macOS.
  • [DATA_EXFILTRATION]: The skill combines read access to sensitive local data with the ability to send messages to various external network endpoints.
  • Evidence: Reads local profile data (contact_*.md), user preferences (preferences.md, preferences.json), and restrictions (donts.md) from the plugin data directory. This data could potentially be exfiltrated if the agent is manipulated into sending it via one of the integrated communication channels.
  • [DYNAMIC_EXECUTION]: The skill executes a local script for Discord integration.
  • Evidence: Calls ${CLAUDE_PLUGIN_ROOT}/bin/ops-discord with arguments derived from natural language parsing to send and read Discord messages.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:50 PM