team-builder

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection by ingesting external markdown content and directly interpolating it into subagent prompts without proper isolation.
  • Ingestion points: The skill recursively probes ./agents/, ~/.claude/agents/, and optional user-specified paths for markdown files to use as agent personas (Step 1).
  • Boundary markers: There are no delimiters or 'ignore' instructions used when constructing the final prompt: "{agent file content}\n\nTask: {task description}" (Step 4).
  • Capability inventory: The skill utilizes the Agent tool to spawn subagents with subagent_type: "general-purpose" (Step 4).
  • Sanitization: No sanitization, escaping, or validation is performed on the content of the agent files before they are executed by the subagent.
  • [COMMAND_EXECUTION]: The skill dynamically loads and executes the content of filesystem objects using the Agent tool. If an attacker manages to place a malicious markdown file in a directory searched by the skill (e.g., through a cloned repository), the skill will execute the attacker's instructions with the full capabilities of the subagent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — team-builder