loop-architect
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script scripts/looper.py and the generated runner template templates/run-loop.py utilize subprocess.run to execute external commands. In the runner, these commands are arbitrary argv arrays specified in the loop configuration, allowing for untrusted command execution if the spec is malicious.
- [DATA_EXFILTRATION]: The templates/run-loop.py script includes a privacy redaction feature that programmatically reads sensitive files (e.g., .env, secrets, and keys) to replace their content in prompts. While intended for privacy, this involves direct access to sensitive data which could be abused.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data sources into the agent context. 1. Ingestion points: goal.context_sources in specification files like examples/ai-workflow-mapping/loop.yaml. 2. Boundary markers: Absent in the generated prompt templates. 3. Capability inventory: subprocess.run and file writing in run-loop.py and looper.py. 4. Sanitization: Redaction logic is present for secrets but does not filter malicious instructions within ingested content.
- [DYNAMIC_EXECUTION]: The skill generates and emits a standalone Python script (run-loop.py) to the user's workspace, which is then executed to orchestrate the iterative loop process.
Audit Metadata