autonomous-loops
Fail
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides an installation command for the 'continuous-claude' tool using a high-risk pattern: piping a remote script from GitHub directly into bash ('curl ... | bash'). This executes unverified code without a preceding review step.
- Evidence: Found in SKILL.md:
curl -fsSL https://raw.githubusercontent.com/AnandChowdhary/continuous-claude/HEAD/install.sh | bash - [EXTERNAL_DOWNLOADS]: The skill references and downloads tools and configurations from an external, third-party GitHub repository ('AnandChowdhary/continuous-claude') that is not affiliated with the skill author.
- [COMMAND_EXECUTION]: The loop patterns described involve autonomous execution of shell commands and CLI tools (codex, gh, node) as part of development workflows, increasing the potential impact of any malicious instruction.
- [PROMPT_INJECTION]: The autonomous loop architectures described (e.g., Infinite Agentic Loop, Ralphinho) ingest untrusted external data (specs, RFCs) which creates an attack surface for indirect prompt injection.
- Ingestion points: External specification files (e.g., docs/auth-spec.md) and RFC documents entering the loop context.
- Boundary markers: None documented in the instructions; loops appear to ingest text directly into prompts via file reading.
- Capability inventory: The agents are granted capabilities for filesystem modification, shell command execution (codex, gh), and repository management.
- Sanitization: No sanitization or validation of the ingested content is described; however, the skill suggests a 'De-Sloppify' pass to manually or programmatically clean up output generated by the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/AnandChowdhary/continuous-claude/HEAD/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata