codemachine-template
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a prompt template system that interpolates external file contents into agent instructions without sanitization or strict boundary markers.
- Ingestion points: Prompt templates in
assets/prompt-template.mdandreferences/prompt-patterns.mduse placeholders such as{{requirements}}and{{tech_spec}}to inject the contents of files from the.codemachine/artifacts/directory directly into the LLM context. - Boundary markers: The templates rely on standard Markdown headers (e.g.,
## Required Inputs) but do not implement escaping or specific delimiters to prevent embedded instructions in those files from being followed by the agent. - Capability inventory: Agents configured via these templates have the capability to write files (
directive.json, artifacts), call MCP tools for coordination, and execute shell commands via thecodemachineCLI. - Sanitization: There is no evidence of filtering or validation of the content injected via placeholders.
- [DYNAMIC_EXECUTION]: The provided validation utility script employs dynamic code loading to verify workflow configurations.
- Evidence: The file
assets/validate-workflow.mjsuses theimport()function (line 197) to load and execute JavaScript workflow files provided as command-line arguments. While intended for development-time validation, this allows for the execution of arbitrary code within the context of the script. - [COMMAND_EXECUTION]: The skill instructions and documentation describe workflows where agents are expected to execute various shell commands.
- Evidence: Documentation in
SKILL.mdandreferences/orchestration-patterns.mddetails the use of thecodemachine runCLI for parallel and sequential agent execution, as well as the execution of build and test commands (e.g.,npm test,npx tsc) within agent prompts.
Audit Metadata