driver
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core logic is driven by the contents of files such as
MISSION.md,AGENTS.md, andCHOICES.md, which are sourced from the project repository. - Ingestion points:
SKILL.mdandsys_driver.mdexplicitly instruct the agent to read these markdown files to determine its objective and task list. - Boundary markers: The instructions do not specify any delimiters or sanitization protocols for the content of these files before they are processed.
- Capability inventory: The skill is capable of performing
git mergeoperations, spawning background workers, and executing production deployments. - Sanitization: The risk is mitigated by the mandatory use of the
defendskill family (DefendPlan,DefendMerge,DefendRelease), which routes critical decisions through high-tier models (Anthropic Opus) for verification. - [COMMAND_EXECUTION]: The skill interacts with the system via specialized command-line tools and shell operations.
- Evidence: Uses
herdrfor managing persistent panes andbeadsCLI for querying and updating task states. - Evidence: Performs
git mergeoperations as part of the code integration workflow. - [REMOTE_CODE_EXECUTION]: The skill delegates work to ephemeral agents, which involves spawning and monitoring new processes.
- Evidence: Utilizes
bg_delegateandbg_run_pi_attestedto run worker agents. Thebg_run_pi_attestedpattern suggests the use of process isolation and attestation for security when executing worker code.
Audit Metadata