skills/boshu2/agentops/agy-native/Gen Agent Trust Hub

agy-native

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external "packets" and workspace data, which creates a surface for instructions embedded in that data to influence agent behavior.
  • Ingestion points: Untrusted data enters the context through the "supplied workspace and packet" mentioned in the setup instructions.
  • Boundary markers: The instructions do not define specific delimiters or explicit instructions for the agent to ignore commands found within the packet content.
  • Capability inventory: The skill uses the agy CLI tool which has the capability to dispatch packets, start sessions, and perform tool calls (SKILL.md).
  • Sanitization: No sanitization, filtering, or validation steps are described for the incoming packet data.
  • [COMMAND_EXECUTION]: The skill documents the use of the agy CLI tool and specifically mentions the --dangerously-skip-permissions flag.
  • Evidence: This flag "auto-approves every tool call," effectively bypassing interactive user consent for actions taken by the runtime. While the skill instructs the agent to "name it explicitly" and use it only when authorized, the documentation of this permission-bypass mechanism increases the potential impact if the agent is subverted by malicious input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:34 AM
Security Audit — agent-trust-hub — agy-native