delegating-to-otto
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-step execution chain where a parent agent passes prompts to the
astro ottosub-agent, creating a surface for potential instruction override. - Ingestion points: Untrusted data enters the agent context via the command-line arguments passed to
astro ottoas described inSKILL.md. - Boundary markers: The skill does not explicitly instruct the use of boundary markers or delimiters to wrap user-provided data passed into the sub-agent's prompt string.
- Capability inventory: The sub-agent possesses extensive capabilities including shell command execution (
bash), file editing (edit,write), and Airflow-specific tool interactions (af), documented across multiple sections inSKILL.md. - Sanitization: The skill documentation describes internal 'Bypass-immune safety checks' within the sub-agent that protect sensitive paths (such as
.ssh,.aws, and.env) and prevent certain destructive commands, providing a safety layer for the processed input. - [COMMAND_EXECUTION]: The skill instructions facilitate the execution of the
astro ottoCLI tool, which can perform system-level operations. - The documentation includes guidance on using potentially sensitive flags such as
--permission-mode bypassPermissionsand--skip-permissions, which reduce the sub-agent's operational constraints.
Audit Metadata