skills/agent-sh/agentsys/debate/Gen Agent Trust Hub

debate

Warn

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to build and execute shell commands using bash to invoke various AI CLI tools (claude, gemini, codex, opencode, copilot). It explicitly instructs the agent to bypass platform-standard skill invocation methods.
  • [DYNAMIC_EXECUTION]: The skill relies on the runtime generation of shell commands and the execution of local scripts (e.g., node acp/run.js) to facilitate the debate process.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input and uses it in security-sensitive contexts.
  • Ingestion points: Debate topics from $ARGUMENTS and responses from participating AI tools.
  • Boundary markers: The prompt templates do not include specific delimiters or instructions to prevent the agent from following instructions embedded in the debate content.
  • Capability inventory: The skill has the ability to execute shell commands, read and write files in the {AI_STATE_DIR}, and interact with external network services via CLI tools.
  • Sanitization: No instructions are provided for escaping or sanitizing debate topics or tool responses to prevent command injection when building shell commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 5, 2026, 12:08 AM
Security Audit — agent-trust-hub — debate