intent-detection
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains a directive to explicitly bypass platform security mechanisms. In
SKILL.md, it instructs the agent to always usemode: "bypassPermissions"when spawning other agents via the Agent tool. The documentation notes this is intended to avoid "permission prompts during unattended execution," which directly overrides the user's ability to review and approve agent actions. - [COMMAND_EXECUTION]: The skill acts as a central orchestrator capable of triggering numerous high-privilege agents and skills defined in
agent-triggers.yaml, such asinfra-aws-expert,db-supabase-expert, andcodex-exec. Because it is instructed to bypass permissions, it can initiate complex sequences of commands and system modifications (cloud infra, database migrations, code execution) without authorization. - [CREDENTIALS_UNSAFE]: The research workflow routing logic in
SKILL.mdidentifies a dependency on theOPENAI_API_KEYenvironment variable. While no key is hardcoded, the skill is designed to automatically utilize these sensitive credentials in a context where user permission prompts have been intentionally suppressed.
Recommendations
- AI detected serious security threats
Audit Metadata