glm-delegation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary text prompts and file contents which are then analyzed by an LLM via the
claudebinary. This creates a surface where malicious instructions embedded in external files could potentially influence agent behavior. - Ingestion points: The skill ingest data via the
PROMPTenvironment variable and the--filescommand-line argument as shown inSKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are documented for the input data.
- Capability inventory: The skill utilizes the
claudebinary anddelegation_executor.py, which have capabilities for reasoning, tool use, and file system interaction. - Sanitization: There is no evidence of sanitization or filtering applied to the external content before it is processed by the model.
- [EXTERNAL_DOWNLOADS]: The skill instructions include the installation of the
@anthropic-ai/claude-codepackage from the official NPM registry, which is a well-known service. - [COMMAND_EXECUTION]: The skill executes shell commands to perform delegation, including the
claudeCLI and a local Python scriptdelegation_executor.py. These commands utilize environment variables to swap API endpoints for redirection.
Audit Metadata