consult
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes external AI CLI tools including
claude,gemini,codex,opencode, andcopilot. These executions are parameterized with user-supplied flags that are filtered for shell metacharacters. - [EXTERNAL_DOWNLOADS]: The skill uses
npxto download and execute ACP adapters for Claude and Codex. These packages (@anthropic-ai/claude-code-acpand@zed-industries/codex-acp) originate from well-known and reputable organizations. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external AI tool responses and local files via the
--contextargument, creating a surface for embedded instructions. - Ingestion points: Tool outputs (stdout), context files (via Read tool).
- Boundary markers: None explicitly implemented for tool response interpolation.
- Capability inventory: Command execution of CLI tools, file writing (temporary question files), and file reading.
- Sanitization: Implements an extensive regex-based redaction system for API keys (Anthropic, OpenAI, Google, GitHub, AWS) and Authorization headers.
- [DYNAMIC_EXECUTION]: The skill dynamically builds shell commands from templates and executes a local script (
acp/run.js) to handle ACP transport for specific providers.
Audit Metadata