multi-model-verification
Fail
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: HIGHPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a directive to use
mode: "bypassPermissions"when calling theAgenttool. This instruction is explicitly designed to suppress platform permission prompts during "unattended execution", bypassing user oversight and safety controls. - [PROMPT_INJECTION]: The skill provides instructions for the agent to potentially override its own configuration regarding permission modes, stating that the tool's
bypassPermissionsmode should be used to override the defaultacceptEditsorpermissionModesettings. - [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis:
- Ingestion points:
SKILL.md(Workflow section) identifies input as "File path(s) or diff to verify". - Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the sub-agents to ignore embedded instructions within the code being reviewed.
- Capability inventory: The skill spawns multiple sub-agents using the
Agenttool with the capability to perform Architecture, Quality, and Style reviews, coupled with the instruction to bypass permissions. - Sanitization: Absent. There is no evidence of input validation or sanitization before the code is passed to the reviewer agents.
Recommendations
- AI detected serious security threats
Audit Metadata