chief-of-staff

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a variety of command-line tools to retrieve data, including gog (Gmail CLI), td (Todoist CLI), git-commits, mochi, and ssh (specifically to query a WhatsApp SQLite database on a remote host named 'mini'). It also runs local Python and shell scripts (generate_digest.py, active-directories.sh, update-day-schedule.py) to process this information.
  • [DATA_EXFILTRATION]: The skill's operation results in the exposure of significant amounts of sensitive personal data to the agent's context. This includes unread email content from multiple accounts, private WhatsApp messages, calendar details, and internal project notes (CLAUDE.md, AGENTS.md, people.json). This data is read and summarized to provide the daily briefing and recap.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it ingests and processes untrusted text from external communication channels (emails and WhatsApp messages). This content is used to influence the agent's summaries and 'What can I help with?' suggestions. \n
  • Ingestion points: Email triage search results and WhatsApp message logs (via SQLite). \n
  • Boundary markers: No specific delimiters or 'ignore' instructions are provided in the SKILL.md to safeguard the agent from instructions that might be embedded in the fetched messages. \n
  • Capability inventory: The agent has permissions to read/write local files (briefings, Obsidian notes) and execute a wide range of productivity and system CLI tools. \n
  • Sanitization: The skill lacks logic to sanitize or validate external message content before it is interpolated into the agent's reasoning loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 10:24 PM
Security Audit — agent-trust-hub — chief-of-staff