workmachine
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's initialization phase requires the agent to execute a local shell script (
scaffold/init.sh) to set up the working directory and render template files. - [COMMAND_EXECUTION]: The agent uses shell commands such as
date +%sfor timeboxing andgit logto verify subagent contributions. - [INDIRECT_PROMPT_INJECTION]: The skill operates an autonomous loop that ingests untrusted user input and subagent reports. Ingestion points: User-defined goal and duration arguments; subagent status lines in
progress.md. Boundary markers: Explicit structured files (state.md,machine.md) and pre-defined role prompts in theprompts/folder. Capability inventory: Shell script execution, file manipulation, and recursive model dispatches. Sanitization: Instructions mandate a mechanical orchestrator that only reads one-line "tiny returns" from subagents. - [DYNAMIC_EXECUTION]: The skill populates role-specific prompt templates with runtime variables during setup, creating the instructional context for all subsequent subagent actions.
Audit Metadata