codemachine-template

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a prompt template system that interpolates external file contents into agent instructions without sanitization or strict boundary markers.
  • Ingestion points: Prompt templates in assets/prompt-template.md and references/prompt-patterns.md use placeholders such as {{requirements}} and {{tech_spec}} to inject the contents of files from the .codemachine/artifacts/ directory directly into the LLM context.
  • Boundary markers: The templates rely on standard Markdown headers (e.g., ## Required Inputs) but do not implement escaping or specific delimiters to prevent embedded instructions in those files from being followed by the agent.
  • Capability inventory: Agents configured via these templates have the capability to write files (directive.json, artifacts), call MCP tools for coordination, and execute shell commands via the codemachine CLI.
  • Sanitization: There is no evidence of filtering or validation of the content injected via placeholders.
  • [DYNAMIC_EXECUTION]: The provided validation utility script employs dynamic code loading to verify workflow configurations.
  • Evidence: The file assets/validate-workflow.mjs uses the import() function (line 197) to load and execute JavaScript workflow files provided as command-line arguments. While intended for development-time validation, this allows for the execution of arbitrary code within the context of the script.
  • [COMMAND_EXECUTION]: The skill instructions and documentation describe workflows where agents are expected to execute various shell commands.
  • Evidence: Documentation in SKILL.md and references/orchestration-patterns.md details the use of the codemachine run CLI for parallel and sequential agent execution, as well as the execution of build and test commands (e.g., npm test, npx tsc) within agent prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — codemachine-template