skills/poteto/noodle/execute/Gen Agent Trust Hub

execute

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent to spawn teammates or sub-agents using a mode: "bypassPermissions" configuration in references/team-execution.md. This represents a high-severity security risk as it explicitly attempts to circumvent platform-level access controls and safety restrictions intended to limit the scope of automated tasks.
  • [PROMPT_INJECTION]: The SKILL.md file contains instructions that attempt to override standard agent safety and interaction behaviors. Specifically, it directs the agent to "Operate fully autonomously," "Never ask the user," and "Don't stop until the work is fully complete," which removes human-in-the-loop oversight for potentially dangerous operations.
  • [COMMAND_EXECUTION]: The workflow relies heavily on executing shell commands for repository management, build processes, and testing via tools like noodle, git, pnpm, and go. In SKILL.md, it also uses shell variables like $NOODLE_SESSION_ID to emit events. When combined with the autonomous operation and bypassed permissions, these capabilities significantly increase the potential impact of a compromise.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from external sources such as plans and todo lists, creating an attack surface where malicious data could influence the agent's behavior.
  • Ingestion points: Files located in brain/plans/, brain/todos.md, and brain/principles/ are read to determine the scope and logic of execution.
  • Boundary markers: The instructions do not define any delimiters or safety headers to distinguish between project data and instructions in these external files.
  • Capability inventory: The skill can execute shell commands, manage system worktrees, and spawn sub-agents with elevated privileges.
  • Sanitization: There is no evidence of validation, escaping, or sanitization for the content retrieved from the plans or todos before it is processed by the agent or passed to sub-agents.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 03:00 AM