dispatch-bible

Fail

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill introduces a 'yolo' mode explicitly designed to skip confirmation gates and auto-approve actions, which encourages bypassing standard safety protocols and human-in-the-loop requirements.
  • [COMMAND_EXECUTION]: Provides templates and instructions for establishing persistence on the system using cron jobs for scheduled execution of background tasks (e.g., 'overnight-build.sh' and weekly reviews).
  • [PROMPT_INJECTION]: The execution model relies on the agent reading and executing instructions directly from external, user-editable files such as 'tasks/todo.md' and 'tasks/batch-queue.json'. \n
  • Ingestion points: 'tasks/todo.md' and 'tasks/batch-queue.json' (SKILL.md) \n
  • Boundary markers: None identified; instructions extracted from these files are treated as authoritative commands for the headless agent. \n
  • Capability inventory: Full tool access through recursive 'claude --headless' calls, shell execution (bash), and file system modification. \n
  • Sanitization: None; the skill lacks any validation or escaping mechanism for the content read from external task files.
  • [DATA_EXFILTRATION]: Documents patterns for sending task results and logs to external services via the Telegram Bot API and Slack webhooks using curl.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 1, 2026, 05:35 AM
Security Audit — agent-trust-hub — dispatch-bible