system-bus
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages
Bun.spawnandBun.$to execute shell commands and system utilities. It specifically utilizes thepiCLI to perform LLM-driven tasks and PRD story execution on the host machine. - [PERSISTENCE]: The skill instructions involve configuring and managing macOS
launchdagents, specificallycom.joel.content-sync-watcher.plist, to maintain background monitoring and synchronization tasks. - [INDIRECT_PROMPT_INJECTION]: The worker is designed to ingest and process data from external untrusted sources, creating a potential vector for malicious instructions to influence LLM behavior.
- Ingestion points: Data enters the system via GitHub webhooks, Front email thread history, and Vercel notifications processed in
src/webhooks/providers/. - Boundary markers: The provided documentation does not specify explicit boundary markers or "ignore" instructions for the ingested content.
- Capability inventory: The skill has extensive capabilities including filesystem access, subprocess execution (
Bun.spawn), and the ability to launch Kubernetes jobs. - Sanitization: The documentation notes basic normalization such as white-space stripping and character capping for search queries, but lacks comprehensive sanitization for prompt interpolation.
- [DYNAMIC_EXECUTION]: Through the
system/agent-dispatchfunction, the skill can dynamically generate and execute scripts or "stories" in either a local host environment or an isolated Kubernetes sandbox.
Audit Metadata