loop-nanny
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill explicitly instructs the agent to modify the source code of its primary CLI tool (
joelclaw) located at~/Code/joelhooks/joelclaw/and then execute the modified code to 'improve' the tool during its monitoring tasks. - Evidence: Section 'Improve joelclaw While You Nanny' details modifying files in
packages/cli/src/and testing changes usingjoelclaw <command>. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from story attempt output files created by other agent processes, which it then uses to make triage and cleanup decisions.
- Ingestion points:
/tmp/agent-loop/<LOOP_ID>/<STORY_ID>-<ATTEMPT>.outfiles containing implementor/reviewer reasoning and diffs. - Boundary markers: Absent. The skill reads these files via
catandtailwithout delimiters or instructions to ignore embedded commands. - Capability inventory: The skill has extensive capabilities including file deletion (
rm), Kubernetes deployment restarts (kubectl), and git modifications. - Sanitization: Absent. The agent is directed to grep for patterns and read verdicts directly from these potentially untrusted outputs.
- [COMMAND_EXECUTION]: The skill performs several powerful system operations including recursively deleting files, force-removing git worktrees, and restarting Kubernetes deployments.
- Evidence: Commands such as
rm <project>/__tests__/<prefix>-*.test.ts,kubectl -n joelclaw rollout restart, andgit worktree remove ... --force.
Audit Metadata