ops-orchestrate

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEPERSISTENCEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to search for and resolve highly sensitive credentials, including GITHUB_TOKEN, SENTRY_AUTH_TOKEN, LINEAR_API_KEY, and ANTHROPIC_API_KEY, from the user's environment, Doppler, or password managers.
  • [PERSISTENCE]: The instructions implement a persistent execution model, specifically a WHILE true loop in Phase 6 designed to keep the agent running autonomously until all tasks are finished or manually interrupted. The skill also utilizes CronCreate capabilities to schedule recurring tasks.
  • [DYNAMIC_EXECUTION]: In Phase 4 (Audit), the skill executes eval "<quality_gate command>" using strings stored in task metadata. Since this metadata is generated based on project audits and external data sources, it provides a vector for arbitrary command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface, ingesting and processing data from numerous untrusted external sources including GitHub PR comments, issue descriptions, CI logs, Sentry error reports, and Linear tickets. There are no instructions for sanitizing this data before it is passed to subagents.
  • [PROMPT_INJECTION]: The skill uses directive language intended to bypass standard AI safety and oversight protocols, such as 'No preamble. No "would you like me to". Execute immediately' and 'Do not ask for confirmation'.
  • [COMMAND_EXECUTION]: The skill makes extensive use of powerful shell commands and automated PR merging with admin privileges (gh pr merge --admin), which increases the potential impact of any successful injection or logic error.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 09:46 PM