implement-unattended

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions explicitly direct the agent to override safety and confirmation protocols of related skills. In unattended.md, it states regarding grant-naming-authority and grant-decision-authority: "Their gate paragraphs are satisfied — do not stop and ask." This is a direct instruction to ignore built-in human-in-the-loop safeguards intended to verify delegated authority.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection due to its handling of untrusted data.
  • Ingestion points: The skill ingests data from external issue URLs, ticket numbers, and repository-specific configuration files such as AGENTS.md and CLAUDE.md.
  • Boundary markers: The skill does not define any delimiters or specific instructions to prevent the agent from executing instructions potentially embedded within the ticket data or repository files.
  • Capability inventory: The skill environment possesses broad capabilities including file system manipulation (git worktree), branch merging, pull request creation, and the ability to dispatch subagents with delegated authority.
  • Sanitization: There is no evidence of input validation, escaping, or sanitization of the processed data before it is used to brief subagents or influence decision-making.
  • [COMMAND_EXECUTION]: The workflow relies on shell commands for searching the codebase (grep) and managing worktrees/merges (git). These commands are executed during an unattended session, meaning the results and any potential side effects are not reviewed by a human until the entire process completes and a PR is generated.
  • [PRIVILEGE_ESCALATION]: The skill implements a logical mechanism to delegate 'decision authority' and 'naming authority' to the AI agent. This effectively increases the agent's autonomous capabilities beyond standard limits by instructing it to make architectural and terminology choices that would normally require explicit human confirmation, deferring all review to a post-action pull request.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 12:38 PM
Security Audit — agent-trust-hub — implement-unattended