claude-code-ping-start-5h-quota

Warn

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses run_in_background to execute shell commands like caffeinate and sleep combined with the Claude CLI. While this is the primary purpose of the skill, backgrounding persistent tasks can be used to hide activity from users.
  • [PRIVILEGE_ESCALATION]: In the Troubleshooting section, the skill explicitly instructs the agent to use dangerouslyDisableSandbox: true if the caffeinate command is blocked by the platform's security sandbox. This is a direct instruction to bypass security controls.
  • [METADATA_POISONING]: The skill includes a .security-scan-passed file which attempts to claim the skill has been pre-verified by external tools. This is a deceptive metadata pattern intended to influence the judgment of automated scanners or human reviewers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 29, 2026, 06:13 PM
Security Audit — agent-trust-hub — claude-code-ping-start-5h-quota