autonomous-loops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents patterns for orchestrating autonomous development loops using shell scripts, sequential claude -p subprocess calls, and integration with the GitHub CLI (gh). These patterns automate filesystem modifications, test execution, and pull request management.
  • [INDIRECT_PROMPT_INJECTION]: Several architectures described (e.g., 'Infinite Agentic Loop', 'Continuous Claude PR Loop', and 'Ralphinho') ingest untrusted external data to drive agent actions. This data includes specification files, RFC/PRD documents, and remote CI logs fetched via gh run view.
  • Ingestion points: SKILL.md details processes that read docs/auth-spec.md, specs/component-spec.md, SHARED_TASK_NOTES.md, and CI output to plan subsequent implementation steps.
  • Boundary markers: The provided prompt templates and orchestration logic lack explicit delimiters or instructions to ignore embedded malicious commands within the ingested data.
  • Capability inventory: The agents described in these loops typically possess filesystem write permissions, subprocess execution capabilities (via the Bash tool), and network interaction capabilities (via GitHub CLI).
  • Sanitization: The skill does not mention validation, escaping, or filtering of the external content before it is interpolated into agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — autonomous-loops