intent-detection

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a directive to explicitly bypass platform security mechanisms. In SKILL.md, it instructs the agent to always use mode: "bypassPermissions" when spawning other agents via the Agent tool. The documentation notes this is intended to avoid "permission prompts during unattended execution," which directly overrides the user's ability to review and approve agent actions.
  • [COMMAND_EXECUTION]: The skill acts as a central orchestrator capable of triggering numerous high-privilege agents and skills defined in agent-triggers.yaml, such as infra-aws-expert, db-supabase-expert, and codex-exec. Because it is instructed to bypass permissions, it can initiate complex sequences of commands and system modifications (cloud infra, database migrations, code execution) without authorization.
  • [CREDENTIALS_UNSAFE]: The research workflow routing logic in SKILL.md identifies a dependency on the OPENAI_API_KEY environment variable. While no key is hardcoded, the skill is designed to automatically utilize these sensitive credentials in a context where user permission prompts have been intentionally suppressed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — intent-detection