skills/joelhooks/joelclaw/system-bus/Gen Agent Trust Hub

system-bus

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages Bun.spawn and Bun.$ to execute shell commands and system utilities. It specifically utilizes the pi CLI to perform LLM-driven tasks and PRD story execution on the host machine.
  • [PERSISTENCE]: The skill instructions involve configuring and managing macOS launchd agents, specifically com.joel.content-sync-watcher.plist, to maintain background monitoring and synchronization tasks.
  • [INDIRECT_PROMPT_INJECTION]: The worker is designed to ingest and process data from external untrusted sources, creating a potential vector for malicious instructions to influence LLM behavior.
  • Ingestion points: Data enters the system via GitHub webhooks, Front email thread history, and Vercel notifications processed in src/webhooks/providers/.
  • Boundary markers: The provided documentation does not specify explicit boundary markers or "ignore" instructions for the ingested content.
  • Capability inventory: The skill has extensive capabilities including filesystem access, subprocess execution (Bun.spawn), and the ability to launch Kubernetes jobs.
  • Sanitization: The documentation notes basic normalization such as white-space stripping and character capping for search queries, but lacks comprehensive sanitization for prompt interpolation.
  • [DYNAMIC_EXECUTION]: Through the system/agent-dispatch function, the skill can dynamically generate and execute scripts or "stories" in either a local host environment or an isolated Kubernetes sandbox.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — system-bus