skills/grahama1970/agent-skills/loop/Gen Agent Trust Hub

loop

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The harness implemented in scripts/loop.py and scripts/scillm_loop_node.py utilizes subprocess.Popen and subprocess.run to execute sub-agent commands. When a command is provided as a string in the configuration, it is executed with shell=True. The harness constructs these commands using templates that interpolate paths and the Python executable.
  • [PERSISTENCE_MECHANISMS]: scripts/render_cron.py and scripts/loop_cron_runner.sh allow the generation of wrapper scripts and crontab entries to schedule loop executions. While the skill instructs the user to install the crontab manually, it contains the infrastructure to maintain recurring execution.
  • [CREDENTIALS_UNSAFE]: scripts/scillm_agent.py contains a hardcoded placeholder API key "sk-dev-proxy-123" used for communication with the Scillm proxy. Although likely a developmental placeholder, it matches the pattern of a sensitive credential.
  • [DATA_EXPOSURE]: The scillm_agent.py script sends prompt data and receives execution results via HTTP POST requests to a configurable base_url, which defaults to "http://localhost:4001" (local proxy). This involves the movement of potentially sensitive prompt context over the network.
  • [DYNAMIC_EXECUTION]: Test fixtures like tests/fixtures/coder_agent.py perform dynamic module loading using importlib.util to execute code generated during the harness run. Additionally, the harness dynamically formats command templates at runtime before execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided objectives which are directly interpolated into the JSON prompts for sub-agents (explorer, coder, code-reviewer).
  • Ingestion points: Objectives are ingested via command-line arguments in scripts/loop.py.
  • Boundary markers: The objective is passed within a structured JSON object to sub-agents, but there are no explicit instructions to ignore or sanitize embedded instructions within the objective text.
  • Capability inventory: The harness possesses capabilities to edit the local repository (coder agent), execute shell commands (loop.py), and perform network requests (scillm_agent.py).
  • Sanitization: The objective text is not sanitized or validated for malicious payloads before being included in the sub-agent prompt context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — loop