minimax-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests local file content to provide context for AI tasks, which can be exploited via indirect prompt injection if the files contain adversarial instructions.\n
  • Ingestion points: delegation_executor.py reads files from the local filesystem to include in the model prompt.\n
  • Boundary markers: Not specified; file content is inlined directly into the command arguments.\n
  • Capability inventory: The skill can read local files, execute shell commands via mmx, and transmit data to the MiniMax API.\n
  • Sanitization: No sanitization or escaping of the inlined file content is mentioned in the documentation.\n- [EXTERNAL_DOWNLOADS]: The skill directs the user to install the mmx-cli package globally via npm from its official repository. This is the legitimate tool for interacting with MiniMax services.\n- [COMMAND_EXECUTION]: The skill relies on executing the mmx binary and a local Python helper script (delegation_executor.py) to perform its tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — minimax-delegation