tether
Warn
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill modifies the agent's configuration at
~/.claude/settings.jsonto installPostToolUsehooks. These hooks trigger the automatic execution of theasciinema-backup-if-activecommand following any tool use by the agent, creating a persistent execution channel. - [PROMPT_INJECTION]: The skill contains 'Self-Evolving' instructions that direct the agent to modify the
SKILL.mdfile itself based on runtime outcomes. This pattern of self-modification can be used to bypass original constraints or alter intended agent behavior over time. - [COMMAND_EXECUTION]: The skill suggests using system-level package managers like Homebrew to install dependencies (
jq) and involves direct write operations to sensitive configuration directories.
Audit Metadata