loop-diagnosis
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
joelclawCLI to perform infrastructure management tasks. This includes modifying Redis state (clearing claims), re-firing events to Inngest, and potentially restarting Kubernetes deployments (system-bus-worker). These are high-privilege operations necessary for the skill's stated purpose of fixing stalled coding loops. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources which could be influenced by untrusted content.
- Ingestion points: System state retrieved from Redis (PRD stories, progress entries, active claims), Inngest API health responses from
localhost:3111, and local worktree content including.outfiles. - Boundary markers: Absent; the skill does not define specific delimiters to distinguish between diagnostic metadata and potentially malicious content within stories or plan entries.
- Capability inventory: The skill can execute the
joelclawCLI to modify system state, restart services, and perform network requests viacurlto local infrastructure endpoints. - Sanitization: No evidence of sanitization or validation is present for the system state data (e.g., story names or error logs in Redis) before it is processed by the agent during diagnosis.
Audit Metadata