loop-worker
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions direct the agent to follow hints such as [LOOP_SUGGESTION] and [CRON_SUGGESTION] which are returned by external MCP tools. This establishes an indirect prompt injection surface where instructions from tool responses could influence the agent's actions.\n
- Ingestion points: Outputs from the mcp__claude-flow__hooks_worker-dispatch and mcp__claude-flow__hooks_worker-status tools.\n
- Boundary markers: There are no markers or system instructions provided to ensure the agent ignores or validates instructions embedded within the tool data.\n
- Capability inventory: The skill utilizes the Bash tool (with npx capability) and the ScheduleWakeup tool for persistence and command execution.\n
- Sanitization: No sanitization or verification logic is defined to check the validity or safety of the instructions returned by the tools.
Audit Metadata