Oathe Security Badge

Is DietrichGebert/ponytail safe?

Yes. DietrichGebert/ponytail is safe to install. Oathe's behavioral security audit gave the ponytail skill by DietrichGebert a trust score of 89/100 with 6 findings, none critical or high. Report updated

https://github.com/DietrichGebert/ponytail

89
SAFE

Is DietrichGebert/ponytail safe to install?

Ponytail is a legitimate AI coding assistant skill that promotes minimal, YAGNI-compliant code generation, with no malicious prompt injection content, data exfiltration, or suspicious network behavior detected. Canary file reads in the monitoring data occurred 6 seconds before the git clone and are definitively attributable to the audit pipeline's own baseline scanning, not the skill. The primary concerns are the persistent shell script registered in ~/.claude/settings.json at install time and the default injection of the ponytail persona into all subagents—both are disclosed plugin behaviors implemented with visible security measures (shell injection protection, once-only nudge flags), but they represent meaningful persistent influence over the user's agent environment.

What security issues were found in DietrichGebert/ponytail?

Category Scores

Prompt Injection 87/100 · 30%
Data Exfiltration 97/100 · 25%
Code Execution 75/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 97/100 · 10%
Behavioral Reasoning 80/100 · 5%

Findings (6)

MEDIUM Lifecycle hooks modify ~/.claude/settings.json and register persistent shell script -25 ▶

The skill registers JavaScript hooks that run on every SessionStart, UserPromptSubmit, and SubagentStart lifecycle event. The activation hook modifies ~/.claude/settings.json to add a 'statusLine' entry pointing to ponytail-statusline.sh, causing a shell script to execute on every Claude Code agent response. This constitutes persistent code execution outside the scope of the conversation. The uninstall.js script correctly handles removal, but this change persists until that script is run.

LOW ACTIVE EVERY RESPONSE persistence directive blocks natural context evolution -8 ▶

The primary ponytail skill declares 'ACTIVE EVERY RESPONSE. No drift back to over-building. Still active if unsure.' This is an unusually aggressive persistence mechanism that overrides natural conversation drift. It requires explicit deactivation phrases ('stop ponytail', 'normal mode', '/ponytail off') to disable, meaning the persona persists even if the user stops explicitly invoking it.

LOW SubagentStart hook injects ponytail persona into all agent sub-processes by default -5 ▶

ponytail-subagent.js runs on SubagentStart and injects the full ponytail coding persona into every subagent the user creates without requiring user opt-in. The PONYTAIL_SUBAGENT_MATCHER environment variable can restrict injection scope, but no matcher is set by default. This means the skill's behavioral influence propagates to all nested or parallel agent processes regardless of whether the user intended that.

INFO Canary files accessed read-only 6 seconds before git clone — audit pipeline, not skill -3 ▶

All six canary honeypot files (.env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, .config/gcloud/application_default_credentials.json) were opened and read at Unix timestamp 1789093676 (02:27:56). The git clone of the ponytail repository did not begin until timestamp 1789093682 (02:28:02), 6 seconds later. Since the ponytail codebase was not present in the sandbox filesystem at the time of access, these reads are definitively attributable to the oathe audit pipeline's own baseline integrity scanning, not to any code from the skill. All files remain unmodified per the official canary integrity check.

INFO Hook writes non-sensitive mode state flag to ~/.claude/ directory -3 ▶

The activation and mode-tracking hooks write a small flag file (~/.claude/.ponytail-active) containing the current mode string ('full', 'ultra', or 'lite'). This is session-state persistence within the user's own home directory and contains no sensitive information. The file is removed by the uninstall script and by the mode-tracker when deactivation phrases are used.

INFO Hook architecture includes security-conscious implementation but creates powerful persistent infrastructure -20 ▶

The hook implementation includes positive security features: isShellSafe() guards against shell metacharacter injection via install paths, statusline nudge is shown at most once (once-only flag), hooks self-exit when stdin never closes to prevent session freeze. However, the same hook architecture would be highly dangerous if replicated in a malicious fork of this skill, as it provides a template for persistent code execution, settings modification, and subagent infiltration. Users should verify installation from the verified DietrichGebert/ponytail source only.

Should I install DietrichGebert/ponytail?

Oathe's verdict for DietrichGebert/ponytail is SAFE with a trust score of 89/100. Recommendation: Install with caution.