team-builder
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection by ingesting external markdown content and directly interpolating it into subagent prompts without proper isolation.
- Ingestion points: The skill recursively probes
./agents/,~/.claude/agents/, and optional user-specified paths for markdown files to use as agent personas (Step 1). - Boundary markers: There are no delimiters or 'ignore' instructions used when constructing the final prompt:
"{agent file content}\n\nTask: {task description}"(Step 4). - Capability inventory: The skill utilizes the
Agenttool to spawn subagents withsubagent_type: "general-purpose"(Step 4). - Sanitization: No sanitization, escaping, or validation is performed on the content of the agent files before they are executed by the subagent.
- [COMMAND_EXECUTION]: The skill dynamically loads and executes the content of filesystem objects using the
Agenttool. If an attacker manages to place a malicious markdown file in a directory searched by the skill (e.g., through a cloned repository), the skill will execute the attacker's instructions with the full capabilities of the subagent.
Audit Metadata