ops-dash
Warn
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to perform various system operations, including updating configuration files, interacting with the system clipboard, and opening web browsers. It specifically instructs the agent to usejqandmvvia shell to modifypreferences.json, which bypasses the explicitdisallowedToolsrestriction on theWriteandEdittools. - [DYNAMIC_CONTEXT_INJECTION]: The skill employs the
!commandsyntax inSKILL.mdto execute the${CLAUDE_PLUGIN_ROOT}/bin/ops-dashbinary automatically when the skill is loaded by the agent, replacing the block with the command output. - [INDIRECT_PROMPT_INJECTION]: The skill processes content from several local files, which serves as a potential attack surface for indirect prompt injection if those files are influenced by untrusted external sources or previous autonomous sessions.
- Ingestion points:
preferences.json,daemon-health.json,registry.json,CHANGELOG.md, and reports located in/tmp/yolo-*/(specifically in Option E). - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within these files.
- Capability inventory: The skill has extensive capabilities including shell execution (Bash), file writing (via Bash), creating agent teams, and browser interaction.
- Sanitization: The skill includes instructions to manually sanitize shared content to prevent secret leakage, but no automated sanitization is described for ingested file data.
- [DATA_EXPOSURE]: The skill is configured to read from
preferences.jsonand temporary report directories in/tmp/, which may contain sensitive business or operational metadata. - Evidence: Access to
${CLAUDE_PLUGIN_DATA_DIR:-$HOME/.claude/plugins/data/ops-ops-marketplace}/preferences.jsonand/tmp/yolo-*/.
Audit Metadata