agent-manager-skill

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from https://github.com/fractalmind-ai/agent-manager-skill.git. This source is external to the skill author (AndrewHaward2310) and is not among the verified technology vendors.
  • [COMMAND_EXECUTION]: Following the download, the skill executes Python scripts (agent-manager/scripts/main.py) from the cloned repository and utilizes tmux for process management. This configuration allows for the execution of arbitrary code defined in the external repository.
  • [PROMPT_INJECTION]: The skill features capabilities to monitor agent outputs and tail logs (monitor EMP_0001 --follow).
  • Ingestion points: Runtime logs and output streams from external CLI agents entering the management context.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Subprocess management via tmux and Python scripts.
  • Sanitization: No sanitization or escaping of the monitored output is described, creating a surface for indirect prompt injection if monitored agents process untrusted data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — agent-manager-skill