life-business-agent
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a persistence mechanism using cron jobs and a 'heartbeat' system that triggers autonomous background actions every 30 minutes, allowing for long-running execution without user supervision.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its architecture of ingesting and processing untrusted data from multiple external channels:
- Ingestion points: Data enters the system via Apple Reminders scraping, Twilio SMS, Telegram Bot messages, and Gmail/Slack via MCP servers.
- Boundary markers: There are no documented boundary markers or instructions to the agent to disregard embedded commands within these external data streams.
- Capability inventory: The agent possesses extensive capabilities including file-system writes (Obsidian vault), network communications (Twilio/Telegram), and interaction with business platforms (Notion, Google Drive, Jira).
- Sanitization: There is no evidence of sanitization or filtering logic to prevent malicious payloads in emails or messages from influencing the agent's autonomous actions.
- [DATA_EXFILTRATION]: The core design involves transferring potentially sensitive data from private environments (local files, emails, CRM) to external messaging platforms (Twilio, Telegram), creating a workflow that could be exploited to exfiltrate personal or business information.
Audit Metadata