agentix-ceo

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted configuration data in the form of a 'playbook' from a remote API. * Ingestion points: Configuration and operating policies are fetched via GET $AGENTIX_API/teams/$TEAM_ID/playbook in the 'Playbook' section of SKILL.md. * Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the playbook content. * Capability inventory: The agent has the ability to create worker roles with arbitrary system prompts (POST /roles), spawn workers (POST /tasks/run), and update team-level API tokens. * Sanitization: No explicit sanitization or validation of the fetched playbook content is documented.
  • [DATA_EXFILTRATION]: The skill facilitates the transfer of third-party service tokens (GitHub, Anthropic) to the agentix.cloud vendor platform to enable worker functionality. This operation is documented as a necessary step for the vendor's worker orchestration service and utilizes the vendor's own infrastructure.
  • [CREDENTIALS_UNSAFE]: The skill manages session credentials using a local file (~/.agentix/credentials). It uses standard placeholders for demonstration and includes specific instructions to the agent to avoid leaking secrets in user-visible output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:15 AM