claude-code-ping-start-5h-quota
Warn
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
run_in_backgroundto execute shell commands likecaffeinateandsleepcombined with the Claude CLI. While this is the primary purpose of the skill, backgrounding persistent tasks can be used to hide activity from users. - [PRIVILEGE_ESCALATION]: In the Troubleshooting section, the skill explicitly instructs the agent to use
dangerouslyDisableSandbox: trueif thecaffeinatecommand is blocked by the platform's security sandbox. This is a direct instruction to bypass security controls. - [METADATA_POISONING]: The skill includes a
.security-scan-passedfile which attempts to claim the skill has been pre-verified by external tools. This is a deceptive metadata pattern intended to influence the judgment of automated scanners or human reviewers.
Audit Metadata