skills/b-open-io/prompts/coordinator/Gen Agent Trust Hub

coordinator

Fail

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to offer the installation of the Grok CLI using a remote shell script from x.ai's official domain.
  • [COMMAND_EXECUTION]: The agent is directed to execute various CLI tools including grok, codex, and npm to manage implementation tasks.
  • [DATA_EXFILTRATION]: Repository context, specifications, and code prompts are sent to external AI vendors (xAI and OpenAI). The skill includes mandatory safeguards requiring the agent to disclose what is being sent and obtain user consent before the first dispatch.
  • [PROMPT_INJECTION]: The skill is exposed to indirect prompt injection from malicious or erroneous code generated by subagents. It defines a robust evidence chain for managing this risk: 1) Ingestion points: Subagent reports, diffs, and log files mentioned in SKILL.md and references/native-workflows.md. 2) Boundary markers: Mandatory use of SPEC files and structured 'FINAL REPORT' sections in worker prompts. 3) Capability inventory: Shell command execution, file system writes, and git management. 4) Sanitization: Detailed instructions for 'Adversarial Review' to detect shims or environment-evasion workarounds, and a requirement to re-run all tests outside the sandboxed worker environment.
Recommendations
  • HIGH: Downloads and executes remote code from: https://x.ai/cli/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 15, 2026, 10:49 PM
Security Audit — agent-trust-hub — coordinator