ops-comms
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external communication channels, creating a surface for indirect prompt injection attacks where malicious instructions in incoming messages could influence the agent's behavior.
- Ingestion points: WhatsApp messages (
wacli), Gmail threads (gog), Slack messages (mcp__claude_ai_Slack), Telegram updates (mcp__claude_ops_telegram), and Notion pages/comments (mcp__claude_ai_Notion). - Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions in the ingested content.
- Capability inventory: Shell command execution (
wacli,gog,curl,launchctl,bin/ops-discord), file read access (viaReadtool and CLI outputs), and network transmission across all configured messaging channels. - Sanitization: Absent; the skill is instructed to summarize and address the content of the messages without explicit sanitization or filtering steps.
- [COMMAND_EXECUTION]: The skill frequently executes shell commands and system utilities to perform its core functions.
- Evidence: Uses
waclifor WhatsApp operations,gogfor Gmail/Calendar,telegram-clias a fallback for Telegram, andcurlfor Notion API requests. It also useslaunchctlto manage thewacli-keepalivedaemon on macOS. - [DATA_EXFILTRATION]: The skill combines read access to sensitive local data with the ability to send messages to various external network endpoints.
- Evidence: Reads local profile data (
contact_*.md), user preferences (preferences.md,preferences.json), and restrictions (donts.md) from the plugin data directory. This data could potentially be exfiltrated if the agent is manipulated into sending it via one of the integrated communication channels. - [DYNAMIC_EXECUTION]: The skill executes a local script for Discord integration.
- Evidence: Calls
${CLAUDE_PLUGIN_ROOT}/bin/ops-discordwith arguments derived from natural language parsing to send and read Discord messages.
Audit Metadata