skills/daxaur/openpaw/c-briefing/Gen Agent Trust Hub

c-briefing

Warn

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides shell commands to generate a local script at ~/.claude/briefing.sh and set its execution permissions using chmod +x.
  • [COMMAND_EXECUTION]: Instructs the user to modify their crontab to achieve persistence for the daily briefing script.
  • [COMMAND_EXECUTION]: References the use of lunchy-go to install a persistent launchd service on macOS.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes untrusted data from multiple integrated skills.
  • Ingestion points: Data enters the agent context from c-email, c-slack, c-github, and other skills.
  • Boundary markers: The briefing template does not utilize specific delimiters or instructions to ignore embedded commands within the ingested content.
  • Capability inventory: The generated briefing is used as input for the claude CLI tool via a scheduled script.
  • Sanitization: No evidence of filtering, escaping, or validation of the external content is present.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 08:44 AM
Security Audit — agent-trust-hub — c-briefing