ralph
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses sensitive local configuration data by reading from
~/.config/claude-omc/config.jsonc. - [DATA_EXFILTRATION]: The skill shares a summary of the task, current progress, and modified code areas with an external tool through the
companyContext.toolModel Context Protocol (MCP) interface. - [INDIRECT_PROMPT_INJECTION]: The skill operates as a persistence loop that ingests untrusted data from project files and tool outputs to drive its execution logic. 1. Ingestion points: Processes
prd.json,progress.txt, and the results from thecompanyContext.toolMCP call. 2. Boundary markers: Includes a directive to treat tool output as 'quoted advisory context only', but lacks explicit delimiters for state files. 3. Capability inventory: The agent can execute arbitrary shell commands via sub-agents, perform file system operations, and invoke other skills. 4. Sanitization: No explicit sanitization or validation of the ingested state data is performed before it influences the agent's workflow. - [COMMAND_EXECUTION]: The skill instructions prompt the agent to run package management and build commands (e.g.,
npm install,pip install,cargo build), which can lead to the installation and execution of external code from public registries.
Audit Metadata