ralph

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive local configuration data by reading from ~/.config/claude-omc/config.jsonc.
  • [DATA_EXFILTRATION]: The skill shares a summary of the task, current progress, and modified code areas with an external tool through the companyContext.tool Model Context Protocol (MCP) interface.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates as a persistence loop that ingests untrusted data from project files and tool outputs to drive its execution logic. 1. Ingestion points: Processes prd.json, progress.txt, and the results from the companyContext.tool MCP call. 2. Boundary markers: Includes a directive to treat tool output as 'quoted advisory context only', but lacks explicit delimiters for state files. 3. Capability inventory: The agent can execute arbitrary shell commands via sub-agents, perform file system operations, and invoke other skills. 4. Sanitization: No explicit sanitization or validation of the ingested state data is performed before it influences the agent's workflow.
  • [COMMAND_EXECUTION]: The skill instructions prompt the agent to run package management and build commands (e.g., npm install, pip install, cargo build), which can lead to the installation and execution of external code from public registries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 08:41 PM
Security Audit — agent-trust-hub — ralph