debate
Warn
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to build and execute shell commands using
bashto invoke various AI CLI tools (claude,gemini,codex,opencode,copilot). It explicitly instructs the agent to bypass platform-standard skill invocation methods. - [DYNAMIC_EXECUTION]: The skill relies on the runtime generation of shell commands and the execution of local scripts (e.g.,
node acp/run.js) to facilitate the debate process. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input and uses it in security-sensitive contexts.
- Ingestion points: Debate topics from
$ARGUMENTSand responses from participating AI tools. - Boundary markers: The prompt templates do not include specific delimiters or instructions to prevent the agent from following instructions embedded in the debate content.
- Capability inventory: The skill has the ability to execute shell commands, read and write files in the
{AI_STATE_DIR}, and interact with external network services via CLI tools. - Sanitization: No instructions are provided for escaping or sanitizing debate topics or tool responses to prevent command injection when building shell commands.
Audit Metadata