auto-review-loop-minimax
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to read
~/.claude/settings.jsonto retrieve theMINIMAX_API_KEY. This file is a sensitive platform configuration file that may contain multiple other service tokens and secrets, exposing the entire configuration to the agent context. - [COMMAND_EXECUTION]: The skill utilizes
Bash(*)permissions to execute experiments, manage remote sessions via SSH, screen, and tmux, and perform file operations. This provides a broad attack surface for arbitrary command execution. - [DATA_EXFILTRATION]: The skill sends comprehensive project context, including research claims, methods, and results, to the external MiniMax API at
https://api.minimax.io/v1/chat/completions. While this is the skill's primary function, it facilitates the transfer of potentially sensitive intellectual property to an external third-party service. - [DYNAMIC_EXECUTION]: In Phase C, the skill autonomously generates, writes, and modifies experiment scripts and analysis code, which are then executed via Bash. This runtime script generation and execution based on external input is a high-risk pattern.
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from untrusted sources (external API responses and local research files) and uses that data to drive its autonomous "Implement Fixes" phase.
- Ingestion points: Project narrative documents, memory files, and raw responses from the MiniMax API.
- Boundary markers: There are no explicit delimiters or instructions to the agent to ignore potentially malicious commands embedded in the review feedback or project files.
- Capability inventory: The skill has full
Bashaccess, the ability toWriteandEditfiles, and the ability to initiateSSHsessions. - Sanitization: The instructions lack any sanitization or validation steps for the feedback received before it is implemented as code changes or executed as commands.
Recommendations
- AI detected serious security threats
Audit Metadata