ops-yolo

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions direct the agent to resolve high-value credentials including GITHUB_TOKEN, SENTRY_AUTH_TOKEN, LINEAR_API_KEY, and AWS_ACCESS_KEY_ID from environment variables, Doppler, and local password managers.
  • [DATA_EXFILTRATION]: The skill accesses extensive private data sources, including searching both public and private Slack messages (mcp__claude_ai_Slack__slack_search_public_and_private), searching Gmail threads (mcp__claude_ai_Gmail__search_threads), and retrieving AWS cost and usage data.
  • [PERSISTENCE]: The skill utilizes the CronCreate tool to schedule recurring autonomous "YOLO" runs (daily or weekly), allowing it to maintain an active presence and execute actions on the system across sessions.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute multiple shell commands and scripts at load time in Phase 1, including ops-infra, ops-git, ops-ci, and AWS CLI cost exploration, which gathered sensitive system and cloud state data without prior user review.
  • [PRIVILEGE_ESCALATION]: The instructions command the agent to use administrative privileges when merging pull requests (gh pr merge --admin) and accesses centralized secret management tools to elevate its capabilities beyond standard user constraints.
  • [COMMAND_EXECUTION]: Extensive use of the Bash tool to perform operations such as destructive infrastructure changes (e.g., deleting ALBs or stopping RDS instances) and executing complex shell loops to parse JSON and read system files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Slack, Gmail, Linear, and Git PRs to drive its autonomous "C-suite" analysis.
  • Ingestion points: External Slack/Gmail content, Linear issues, and .planning/STATE.md files (SKILL.md).
  • Boundary markers: None identified in the processing of external message content.
  • Capability inventory: Full Bash access, gh and aws CLIs, and tools for file writing and network operations.
  • Sanitization: None identified; the skill processes raw external content to generate "Hard Truths" reports and determine autonomous actions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 09:49 PM