ops-orchestrate
Fail
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to search for and resolve highly sensitive credentials, including
GITHUB_TOKEN,SENTRY_AUTH_TOKEN,LINEAR_API_KEY, andANTHROPIC_API_KEY, from the user's environment, Doppler, or password managers. - [PERSISTENCE]: The instructions implement a persistent execution model, specifically a
WHILE trueloop in Phase 6 designed to keep the agent running autonomously until all tasks are finished or manually interrupted. The skill also utilizesCronCreatecapabilities to schedule recurring tasks. - [DYNAMIC_EXECUTION]: In Phase 4 (Audit), the skill executes
eval "<quality_gate command>"using strings stored in task metadata. Since this metadata is generated based on project audits and external data sources, it provides a vector for arbitrary command injection. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface, ingesting and processing data from numerous untrusted external sources including GitHub PR comments, issue descriptions, CI logs, Sentry error reports, and Linear tickets. There are no instructions for sanitizing this data before it is passed to subagents.
- [PROMPT_INJECTION]: The skill uses directive language intended to bypass standard AI safety and oversight protocols, such as 'No preamble. No "would you like me to". Execute immediately' and 'Do not ask for confirmation'.
- [COMMAND_EXECUTION]: The skill makes extensive use of powerful shell commands and automated PR merging with admin privileges (
gh pr merge --admin), which increases the potential impact of any successful injection or logic error.
Recommendations
- AI detected serious security threats
Audit Metadata