skills/joelhooks/joelclaw/loop-nanny/Gen Agent Trust Hub

loop-nanny

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill explicitly instructs the agent to modify the source code of its primary CLI tool (joelclaw) located at ~/Code/joelhooks/joelclaw/ and then execute the modified code to 'improve' the tool during its monitoring tasks.
  • Evidence: Section 'Improve joelclaw While You Nanny' details modifying files in packages/cli/src/ and testing changes using joelclaw <command>.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from story attempt output files created by other agent processes, which it then uses to make triage and cleanup decisions.
  • Ingestion points: /tmp/agent-loop/<LOOP_ID>/<STORY_ID>-<ATTEMPT>.out files containing implementor/reviewer reasoning and diffs.
  • Boundary markers: Absent. The skill reads these files via cat and tail without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill has extensive capabilities including file deletion (rm), Kubernetes deployment restarts (kubectl), and git modifications.
  • Sanitization: Absent. The agent is directed to grep for patterns and read verdicts directly from these potentially untrusted outputs.
  • [COMMAND_EXECUTION]: The skill performs several powerful system operations including recursively deleting files, force-removing git worktrees, and restarting Kubernetes deployments.
  • Evidence: Commands such as rm <project>/__tests__/<prefix>-*.test.ts, kubectl -n joelclaw rollout restart, and git worktree remove ... --force.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — loop-nanny