ota-updates
Fail
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions designed to override the agent's standard operating procedures and bypass human-in-the-loop requirements, specifically stating "You are in AUTONOMOUS MODE" and "Do NOT pause for confirmation."
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for installing software (Shorebird CLI), initializing project configurations, and running deployment pipelines for mobile applications.
- [DATA_EXPOSURE]: The skill accesses the
~/.claude/projects/directory to record telemetry, which targets a hidden system path used for agent memory and persistent state. - [EXTERNAL_DOWNLOADS]: Fetches and installs dependencies and command-line tools from external services including Shorebird, Expo (EAS Update), and Microsoft (CodePush).
Recommendations
- AI detected serious security threats
Audit Metadata