autonomous-loops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents patterns for orchestrating autonomous development loops using shell scripts, sequential
claude -psubprocess calls, and integration with the GitHub CLI (gh). These patterns automate filesystem modifications, test execution, and pull request management. - [INDIRECT_PROMPT_INJECTION]: Several architectures described (e.g., 'Infinite Agentic Loop', 'Continuous Claude PR Loop', and 'Ralphinho') ingest untrusted external data to drive agent actions. This data includes specification files, RFC/PRD documents, and remote CI logs fetched via
gh run view. - Ingestion points:
SKILL.mddetails processes that readdocs/auth-spec.md,specs/component-spec.md,SHARED_TASK_NOTES.md, and CI output to plan subsequent implementation steps. - Boundary markers: The provided prompt templates and orchestration logic lack explicit delimiters or instructions to ignore embedded malicious commands within the ingested data.
- Capability inventory: The agents described in these loops typically possess filesystem write permissions, subprocess execution capabilities (via the
Bashtool), and network interaction capabilities (via GitHub CLI). - Sanitization: The skill does not mention validation, escaping, or filtering of the external content before it is interpolated into agent prompts.
Audit Metadata