do-agent

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses direct interpolation of user input via $ARGUMENTS without any boundary markers or sanitization, making it vulnerable to injection attacks that could redefine the execution plan.
  • [PROMPT_INJECTION]: Instructions explicitly mandate bypassing human-in-the-loop safety measures, stating "Do not ask for plan approval" and "Complete automation ... without any human intervention."
  • [COMMAND_EXECUTION]: The skill grants full Bash tool access to all sub-agents and encourages autonomous execution, which can lead to arbitrary command execution on the host system.
  • [DATA_EXFILTRATION]: By granting full Read and Bash capabilities to autonomous sub-agents while processing untrusted input, the skill creates a significant risk of local file exposure or exfiltration if a sub-agent is manipulated.
  • [PROMPT_INJECTION]: The skill uses directive language like "严禁" (strictly prohibit) and "must allow" to override default agent behaviors and safety constraints regarding tool usage and reporting.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 03:10 AM
Security Audit — agent-trust-hub — do-agent