automate-before-manual

Fail

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill explicitly directs the agent to access sensitive credential files located outside the project workspace using relative paths like ../secrets/github/pat.txt and ../secrets/vps/ssh/. This promotes directory traversal for harvesting private tokens and keys.- [INDIRECT_PROMPT_INJECTION]: The agent is instructed to read configuration files such as AGENTS.md and secrets.local.md to determine the location of sensitive vaults, creating a vulnerability where an attacker could influence the agent's file access by modifying these repository files.- [COMMAND_EXECUTION]: The instructions mandate the use of powerful automation tools including the Azure CLI (az), GitHub CLI (gh), and SSH, while specifically instructing the agent not to ask for user permission when keys are available.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 10, 2026, 06:37 PM
Security Audit — agent-trust-hub — automate-before-manual