orbit
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill generates and executes shell scripts (
run-loop.sh,bootstrap.sh,verify.sh) that perform arbitrary command execution. It primarily drives AI executors likecodex,claude, andagy(Antigravity) using flags like--dangerously-skip-permissionsor--full-auto, which allow autonomous tool usage without human confirmation. - [DYNAMIC_EXECUTION]: The skill's core functionality involves runtime generation of executable bash scripts from templates. It uses
bash -cto execute user-defined or template-derivedEXEC_CMDstrings, and utilizes a Perl-based wrapper (portable_timeout) to manage execution lifecycles and timeouts. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from
goal.mdandprogress.md(which may be influenced by external sources or the agent's own prior output) to drive execution loops. This surface is mitigated by requirements for measurable acceptance criteria (AC), independent verification commands, and a separateCRITIC_MODELto gate the completion of tasks. - [EXTERNAL_DOWNLOADS]: The generated
notify.shscript suggests the use of theedge-ttspackage for audio notifications. Additionally, the skill's auditing and verification templates reference several external developer tools and linters (e.g.,jscpd,ts-prune,depcheck,playwright).
Audit Metadata