team-builder
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates sub-agents by retrieving persona instructions from external markdown files and executing them via the platform's Agent tool.
- [DATA_EXPOSURE]: Scans for agent definitions in the project-local
./agents/folder and the global~/.claude/agents/configuration directory. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates the raw, unsanitized content of markdown files directly into the instructions for spawned sub-agents.
- Ingestion points: Reads markdown files from
./agents/**/*.mdand~/.claude/agents/**/*.md. - Boundary markers: None; content is interpolated using a simple template:
"{agent file content}\n\nTask: {task description}". - Capability inventory: Uses the Agent tool to spawn sub-agents which may have code execution or file system access capabilities.
- Sanitization: No validation or sanitization is performed on the content of the markdown files before execution.
Audit Metadata