do-agent
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill uses direct interpolation of user input via
$ARGUMENTSwithout any boundary markers or sanitization, making it vulnerable to injection attacks that could redefine the execution plan. - [PROMPT_INJECTION]: Instructions explicitly mandate bypassing human-in-the-loop safety measures, stating "Do not ask for plan approval" and "Complete automation ... without any human intervention."
- [COMMAND_EXECUTION]: The skill grants full
Bashtool access to all sub-agents and encourages autonomous execution, which can lead to arbitrary command execution on the host system. - [DATA_EXFILTRATION]: By granting full
ReadandBashcapabilities to autonomous sub-agents while processing untrusted input, the skill creates a significant risk of local file exposure or exfiltration if a sub-agent is manipulated. - [PROMPT_INJECTION]: The skill uses directive language like "严禁" (strictly prohibit) and "must allow" to override default agent behaviors and safety constraints regarding tool usage and reporting.
Audit Metadata