agent-manager-skill
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from
https://github.com/fractalmind-ai/agent-manager-skill.git. This source is external to the skill author (AndrewHaward2310) and is not among the verified technology vendors. - [COMMAND_EXECUTION]: Following the download, the skill executes Python scripts (
agent-manager/scripts/main.py) from the cloned repository and utilizestmuxfor process management. This configuration allows for the execution of arbitrary code defined in the external repository. - [PROMPT_INJECTION]: The skill features capabilities to monitor agent outputs and tail logs (
monitor EMP_0001 --follow). - Ingestion points: Runtime logs and output streams from external CLI agents entering the management context.
- Boundary markers: None specified in the instructions.
- Capability inventory: Subprocess management via
tmuxand Python scripts. - Sanitization: No sanitization or escaping of the monitored output is described, creating a surface for indirect prompt injection if monitored agents process untrusted data.
Audit Metadata