continuous-agent-loop
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns in SKILL.md for continuous autonomous loops that ingest untrusted external data, creating a vulnerability surface where instructions embedded in that data could influence agent behavior.
- Ingestion points: SKILL.md references workflows for processing Pull Requests (continuous-pr) and RFC documents (rfc-dag).
- Boundary markers: The instructions in SKILL.md lack defined delimiters or specific warnings for the agent to ignore instructions within the ingested data.
- Capability inventory: The loop pattern in SKILL.md includes session persistence (nanoclaw-repl) and quality gate tools (plankton-code-quality), suggesting significant autonomy and potential write access to the environment.
- Sanitization: No sanitization or validation logic is defined in SKILL.md for the external inputs.
Audit Metadata