randroid-loop

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted data from the repository (task files in .dots/, source code, and verification docs) to drive autonomous actions. This creates an attack surface where instructions embedded in these files could influence the agent to perform unintended actions. 1. Ingestion points: .dots/.md, .dots/.html, repository source code, Docs/VERIFY.md, and user-provided directions. 2. Capability inventory: Execution of build and test tools (e.g., xcodebuild, npm, cargo, pytest), Git operations (commit, push, PR, merge), and file writing. 3. Boundary markers: Instructions require the agent to read repository-specific instructions and provide structured iteration summaries. 4. Sanitization: No explicit sanitization is performed on the content of ingested files before they are processed by the agent.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute various shell commands for project verification and version control. This includes running build systems, test suites, linters, and Git commands for staging, committing, pushing, and merging changes.
  • [DYNAMIC_EXECUTION]: The scripts/randroid-loop.sh wrapper script dynamically constructs agent prompts by reading local reference files and appending user input, then executes these prompts via the codex exec command in a multi-iteration loop.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:27 AM