agent-session-capture-backup
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to read and process local authentication files, specifically
~/.joelclaw/auth.jsonand~/.joelclaw/capture-auth.db, which contain credentials for session capture services. - [COMMAND_EXECUTION]: The skill executes local TypeScript scripts using the
bunruntime and interacts with thejoelclawCLI tool to send messages to remote systems. - [PRIVILEGE_ESCALATION]: The skill performs automatic repairs of environment configuration files, including
.zshrc,.zprofile, and~/.config/system-bus.env. Modifying shell initialization files is a method for environment manipulation and privilege escalation. - [PERSISTENCE]: The skill establishes a daily cron job (
TZ=America/Los_Angeles 15 5 * * *) to maintain scheduled verification and backup tasks across sessions. - [INDIRECT_PROMPT_INJECTION]: The skill ingests raw session capture and transcript data from multiple agents (Pi, Claude Code, and Codex). These transcript files represent untrusted external data which, if containing malicious instructions, could influence the agent's behavior during the backup or repair process.
- Ingestion points: Raw activity sources at
~/.pi/agent/sessions,~/.claude/projects, and~/.codex/sessions. - Boundary markers: None provided in the instructions.
- Capability inventory: File system access, modification of shell configuration files, network requests to a central capture endpoint, and execution of local management scripts.
- Sanitization: No evidence of sanitization or validation of the transcript content before ingestion.
Recommendations
- AI detected serious security threats
Audit Metadata