agent-session-capture-backup

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to read and process local authentication files, specifically ~/.joelclaw/auth.json and ~/.joelclaw/capture-auth.db, which contain credentials for session capture services.
  • [COMMAND_EXECUTION]: The skill executes local TypeScript scripts using the bun runtime and interacts with the joelclaw CLI tool to send messages to remote systems.
  • [PRIVILEGE_ESCALATION]: The skill performs automatic repairs of environment configuration files, including .zshrc, .zprofile, and ~/.config/system-bus.env. Modifying shell initialization files is a method for environment manipulation and privilege escalation.
  • [PERSISTENCE]: The skill establishes a daily cron job (TZ=America/Los_Angeles 15 5 * * *) to maintain scheduled verification and backup tasks across sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests raw session capture and transcript data from multiple agents (Pi, Claude Code, and Codex). These transcript files represent untrusted external data which, if containing malicious instructions, could influence the agent's behavior during the backup or repair process.
  • Ingestion points: Raw activity sources at ~/.pi/agent/sessions, ~/.claude/projects, and ~/.codex/sessions.
  • Boundary markers: None provided in the instructions.
  • Capability inventory: File system access, modification of shell configuration files, network requests to a central capture endpoint, and execution of local management scripts.
  • Sanitization: No evidence of sanitization or validation of the transcript content before ingestion.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 05:04 PM
Security Audit — agent-trust-hub — agent-session-capture-backup