autonomy-engine

Fail

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The TEAM dictionary in SKILL.md contains hardcoded sensitive identifiers and personal information, specifically Telegram user IDs (5220170786, 157228659, 8121728216) and a phone number (+6285811600060).
  • [COMMAND_EXECUTION]: The Decision Authority Matrix explicitly authorizes the agent to 'Deploy code changes' and 'Create new SKILL.md' files with 'FULL' authority and no human review required. This enables the autonomous generation and modification of the agent's executable logic.
  • [DATA_EXFILTRATION]: The skill combines read access to potentially sensitive files (SOUL.md, USER.md, MEMORY.md) with automated capabilities to send Direct Messages (DMs) and post to social media platforms, providing a direct path for data leakage.
  • [PROMPT_INJECTION]: The protocol includes instructions like 'I don't ask permission for things within my authority' and 'Execute autonomously,' which are designed to override standard human-in-the-loop safety constraints and agent control mechanisms.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: 1. Ingestion points: memory/*.md, notes/open-loops.md, and external status checks in SKILL.md. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded content are present. 3. Capability inventory: Code deployment, skill creation, and automated DMs. 4. Sanitization: No evidence of data validation or sanitization of external inputs.
  • [COMMAND_EXECUTION]: The Escalation Protocol includes the automated use of a telegram-userbot to perform repeated phone calls and send voice notes, which could be exploited for automated harassment or unauthorized outbound communication.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 22, 2026, 10:02 AM
Security Audit — agent-trust-hub — autonomy-engine