loop-diagnosis

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the joelclaw CLI to perform infrastructure management tasks. This includes modifying Redis state (clearing claims), re-firing events to Inngest, and potentially restarting Kubernetes deployments (system-bus-worker). These are high-privilege operations necessary for the skill's stated purpose of fixing stalled coding loops.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources which could be influenced by untrusted content.
  • Ingestion points: System state retrieved from Redis (PRD stories, progress entries, active claims), Inngest API health responses from localhost:3111, and local worktree content including .out files.
  • Boundary markers: Absent; the skill does not define specific delimiters to distinguish between diagnostic metadata and potentially malicious content within stories or plan entries.
  • Capability inventory: The skill can execute the joelclaw CLI to modify system state, restart services, and perform network requests via curl to local infrastructure endpoints.
  • Sanitization: No evidence of sanitization or validation is present for the system state data (e.g., story names or error logs in Redis) before it is processed by the agent during diagnosis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 AM
Security Audit — agent-trust-hub — loop-diagnosis