loop
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The harness implemented in
scripts/loop.pyandscripts/scillm_loop_node.pyutilizessubprocess.Popenandsubprocess.runto execute sub-agent commands. When a command is provided as a string in the configuration, it is executed withshell=True. The harness constructs these commands using templates that interpolate paths and the Python executable. - [PERSISTENCE_MECHANISMS]:
scripts/render_cron.pyandscripts/loop_cron_runner.shallow the generation of wrapper scripts and crontab entries to schedule loop executions. While the skill instructs the user to install the crontab manually, it contains the infrastructure to maintain recurring execution. - [CREDENTIALS_UNSAFE]:
scripts/scillm_agent.pycontains a hardcoded placeholder API key "sk-dev-proxy-123" used for communication with the Scillm proxy. Although likely a developmental placeholder, it matches the pattern of a sensitive credential. - [DATA_EXPOSURE]: The
scillm_agent.pyscript sends prompt data and receives execution results via HTTP POST requests to a configurablebase_url, which defaults to "http://localhost:4001" (local proxy). This involves the movement of potentially sensitive prompt context over the network. - [DYNAMIC_EXECUTION]: Test fixtures like
tests/fixtures/coder_agent.pyperform dynamic module loading usingimportlib.utilto execute code generated during the harness run. Additionally, the harness dynamically formats command templates at runtime before execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided objectives which are directly interpolated into the JSON prompts for sub-agents (explorer, coder, code-reviewer).
- Ingestion points: Objectives are ingested via command-line arguments in
scripts/loop.py. - Boundary markers: The objective is passed within a structured JSON object to sub-agents, but there are no explicit instructions to ignore or sanitize embedded instructions within the objective text.
- Capability inventory: The harness possesses capabilities to edit the local repository (coder agent), execute shell commands (loop.py), and perform network requests (scillm_agent.py).
- Sanitization: The objective text is not sanitized or validated for malicious payloads before being included in the sub-agent prompt context.
Audit Metadata