delegating-to-otto

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-step execution chain where a parent agent passes prompts to the astro otto sub-agent, creating a surface for potential instruction override.
  • Ingestion points: Untrusted data enters the agent context via the command-line arguments passed to astro otto as described in SKILL.md.
  • Boundary markers: The skill does not explicitly instruct the use of boundary markers or delimiters to wrap user-provided data passed into the sub-agent's prompt string.
  • Capability inventory: The sub-agent possesses extensive capabilities including shell command execution (bash), file editing (edit, write), and Airflow-specific tool interactions (af), documented across multiple sections in SKILL.md.
  • Sanitization: The skill documentation describes internal 'Bypass-immune safety checks' within the sub-agent that protect sensitive paths (such as .ssh, .aws, and .env) and prevent certain destructive commands, providing a safety layer for the processed input.
  • [COMMAND_EXECUTION]: The skill instructions facilitate the execution of the astro otto CLI tool, which can perform system-level operations.
  • The documentation includes guidance on using potentially sensitive flags such as --permission-mode bypassPermissions and --skip-permissions, which reduce the sub-agent's operational constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:33 PM
Security Audit — agent-trust-hub — delegating-to-otto