autonomous-loops

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes architectures such as the 'Infinite Agentic Loop', 'Continuous Claude PR Loop', and 'Ralphinho' which ingest external, potentially untrusted data like specification files (Markdown), RFC/PRD documents, and CI run logs (via gh run view).
  • Ingestion points: RFC documents, project specifications, and GitHub Action logs are read into the agent's context in SKILL.md sections 3, 4, and 6.
  • Boundary markers: The provided templates do not explicitly show the use of delimiters or 'ignore' instructions for external content.
  • Capability inventory: The systems possess full tool access including shell execution (claude -p, bash), file system writes, and Git operations.
  • Sanitization: No mention of sanitization or validation of the ingested external content is present.
  • [COMMAND_EXECUTION]: The skill's core functionality is built upon automated command execution. It extensively uses the claude -p flag to run shell commands for implementation, testing, and cleanup passes. It also utilizes external CLI tools like gh (GitHub CLI) and jj (Jujutsu) for orchestration without manual intervention.
  • [DATA_EXPOSURE]: The NanoClaw REPL pattern (Section 2) stores session conversation history locally in ~/.claude/claw/. While this is standard for the described feature, it represents a centralized location for potentially sensitive project context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — autonomous-loops