agentic-os

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill provides detailed configuration templates (XML for macOS LaunchAgents, INI for Linux systemd, and JS for PM2) to establish persistent, automated execution of the agent across system reboots and user sessions. These templates are designed to execute CLI commands like claude --command /daily-sync on a schedule.
  • [INDIRECT_PROMPT_INJECTION]: The architecture describes an attack surface where agents ingest data from potentially untrusted sources.
  • Ingestion points: The system reads from data/inbox/ and data/logs/ to process tasks and context.
  • Boundary markers: The provided templates for agent identities and command workflows do not include delimiters or instructions to ignore embedded commands in the processed data.
  • Capability inventory: Agents defined in the architecture are explicitly granted full filesystem access, Git operations, and access to Model Context Protocol (MCP) servers.
  • Sanitization: There are no instructions or patterns provided for sanitizing external inputs before they are processed by the specialist agents.
  • [DYNAMIC_EXECUTION]: The orchestration logic (Kernel) dynamically determines which specialist agent to invoke by loading markdown-based instruction sets from the agents/ directory at runtime based on keyword triggers from user input.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — agentic-os