team-builder

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates sub-agents by retrieving persona instructions from external markdown files and executing them via the platform's Agent tool.
  • [DATA_EXPOSURE]: Scans for agent definitions in the project-local ./agents/ folder and the global ~/.claude/agents/ configuration directory.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates the raw, unsanitized content of markdown files directly into the instructions for spawned sub-agents.
  • Ingestion points: Reads markdown files from ./agents/**/*.md and ~/.claude/agents/**/*.md.
  • Boundary markers: None; content is interpolated using a simple template: "{agent file content}\n\nTask: {task description}".
  • Capability inventory: Uses the Agent tool to spawn sub-agents which may have code execution or file system access capabilities.
  • Sanitization: No validation or sanitization is performed on the content of the markdown files before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — team-builder