c-briefing
Warn
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides shell commands to generate a local script at
~/.claude/briefing.shand set its execution permissions usingchmod +x. - [COMMAND_EXECUTION]: Instructs the user to modify their crontab to achieve persistence for the daily briefing script.
- [COMMAND_EXECUTION]: References the use of
lunchy-goto install a persistent launchd service on macOS. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes untrusted data from multiple integrated skills.
- Ingestion points: Data enters the agent context from
c-email,c-slack,c-github, and other skills. - Boundary markers: The briefing template does not utilize specific delimiters or instructions to ignore embedded commands within the ingested content.
- Capability inventory: The generated briefing is used as input for the
claudeCLI tool via a scheduled script. - Sanitization: No evidence of filtering, escaping, or validation of the external content is present.
Audit Metadata