autonomous-loops
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes architectures such as the 'Infinite Agentic Loop', 'Continuous Claude PR Loop', and 'Ralphinho' which ingest external, potentially untrusted data like specification files (Markdown), RFC/PRD documents, and CI run logs (via
gh run view). - Ingestion points: RFC documents, project specifications, and GitHub Action logs are read into the agent's context in SKILL.md sections 3, 4, and 6.
- Boundary markers: The provided templates do not explicitly show the use of delimiters or 'ignore' instructions for external content.
- Capability inventory: The systems possess full tool access including shell execution (
claude -p,bash), file system writes, and Git operations. - Sanitization: No mention of sanitization or validation of the ingested external content is present.
- [COMMAND_EXECUTION]: The skill's core functionality is built upon automated command execution. It extensively uses the
claude -pflag to run shell commands for implementation, testing, and cleanup passes. It also utilizes external CLI tools likegh(GitHub CLI) andjj(Jujutsu) for orchestration without manual intervention. - [DATA_EXPOSURE]: The NanoClaw REPL pattern (Section 2) stores session conversation history locally in
~/.claude/claw/. While this is standard for the described feature, it represents a centralized location for potentially sensitive project context.
Audit Metadata