autonomous-loops
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents architectures where agents autonomously ingest and act upon data from project files, which could contain malicious instructions if the project is compromised.
- Ingestion points: The loops ingest content from files like
docs/auth-spec.md, user-specifiedspec_filepaths,SHARED_TASK_NOTES.md, and CI execution logs retrieved viagh run view. - Boundary markers: The provided prompt templates do not include explicit delimiters or instructions to treat ingested file content as untrusted data.
- Capability inventory: The orchestrated loops have access to subprocess execution (Bash), filesystem modification, and the GitHub CLI for PR and CI management.
- Sanitization: No sanitization or validation of external file content is performed before passing it into the agent's context.
- [COMMAND_EXECUTION]: The skill relies on shell scripts to automate development tasks, including Git operations and the execution of the Claude Code CLI. This behavior is standard for the skill's intended purpose of building autonomous development pipelines.
- [EXTERNAL_DOWNLOADS]: The documentation references external automation tools and repositories. It correctly identifies the risk of remote code and provides safety guidance, advising users to audit external code and avoid piping remote scripts directly to the shell.
Audit Metadata