coordinator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute the Grok CLI installer using
curl -fsSL https://x.ai/cli/install.sh | bash. This targets the official domain of x.ai, which is a well-known AI service. - [EXTERNAL_DOWNLOADS]: The skill includes instructions to install the Codex tool globally using
npm i -g @openai/codex, referencing an official package from OpenAI, a well-known technology service. - [COMMAND_EXECUTION]: The skill manages the execution of various CLI tools including
grok,codex, andnpm. It provides logic for setting up temporary prompt files and configuring environment variables such asXAI_API_KEYandOPENAI_API_KEYfor authenticating worker sessions. - [INDIRECT_PROMPT_INJECTION]: As a coordinator, the skill processes and synthesizes data generated by external workers.
- Ingestion points: File diffs, final reports, and execution logs generated by workers (Grok, Codex, subagents) and task specification files (
SPEC-*.md). - Boundary markers: Uses an "environment clause" to prevent workers from attempting unauthorized environment modifications and requires a "FINAL REPORT" structure to ensure visibility into worker actions.
- Capability inventory: Includes the ability to write to the local filesystem (via worker edits), execute shell commands via bash, and perform network requests through the Grok CLI.
- Sanitization: Instructions mandate the exclusion of secrets and credentials from prompts and require the main agent to perform an "adversarial review" of all worker-generated diffs to check for malicious shims or sandbox escapes.
Audit Metadata