beast-mode

Fail

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly bypass user interaction and safety checks, such as "Do not ask for mid-task confirmation" and "The assistant should never pause to ask the user for input or confirmation mid-task." This overrides standard interaction protocols designed to prevent unauthorized or destructive actions.
  • [COMMAND_EXECUTION]: The "Validation Defaults" section in SKILL.md instructs the agent to "Prefer running the repo's existing checks" and to "Record exact commands run." This encourages the autonomous execution of potentially malicious scripts, tests, or build tools found within an untrusted repository without prior verification or user consent.
  • [REMOTE_CODE_EXECUTION]: The instructions in references/beast-mode.md direct the agent to "fetch provided URLs" and perform "external research" to "update its knowledge." Combined with the autonomous "test-and-fix" workflow, this creates a vector where instructions or code snippets retrieved from external sources could be executed by the agent.
  • [DATA_EXFILTRATION]: The skill mandates gathering context from files, "configs," and "logs" (SKILL.md). In conjunction with the instruction to "perform external research" and fetch URLs, there is a risk that sensitive environment data or configuration secrets could be transmitted to external servers.
  • [PROMPT_INJECTION]: The skill presents a large attack surface for indirect prompt injection. It ingests data from repository scans, logs, and configuration files (SKILL.md) without using boundary markers or sanitization, and has high-privilege capabilities including command execution and file writing. This allows instructions embedded in the processed data to influence the agent's autonomous execution loop.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 19, 2026, 11:54 AM
Security Audit — agent-trust-hub — beast-mode