skills/b-open-io/prompts/coordinator/Gen Agent Trust Hub

coordinator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute the Grok CLI installer using curl -fsSL https://x.ai/cli/install.sh | bash. This targets the official domain of x.ai, which is a well-known AI service.
  • [EXTERNAL_DOWNLOADS]: The skill includes instructions to install the Codex tool globally using npm i -g @openai/codex, referencing an official package from OpenAI, a well-known technology service.
  • [COMMAND_EXECUTION]: The skill manages the execution of various CLI tools including grok, codex, and npm. It provides logic for setting up temporary prompt files and configuring environment variables such as XAI_API_KEY and OPENAI_API_KEY for authenticating worker sessions.
  • [INDIRECT_PROMPT_INJECTION]: As a coordinator, the skill processes and synthesizes data generated by external workers.
  • Ingestion points: File diffs, final reports, and execution logs generated by workers (Grok, Codex, subagents) and task specification files (SPEC-*.md).
  • Boundary markers: Uses an "environment clause" to prevent workers from attempting unauthorized environment modifications and requires a "FINAL REPORT" structure to ensure visibility into worker actions.
  • Capability inventory: Includes the ability to write to the local filesystem (via worker edits), execute shell commands via bash, and perform network requests through the Grok CLI.
  • Sanitization: Instructions mandate the exclusion of secrets and credentials from prompts and require the main agent to perform an "adversarial review" of all worker-generated diffs to check for malicious shims or sandbox escapes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:47 AM
Security Audit — agent-trust-hub — coordinator