agent-builder

Warn

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill enables the configuration of agent 'hooks' for script execution.\n
  • Evidence: agent.template.md and references/frontmatter.md describe a hooks field that allows for a command type, which enables the generated agent to execute arbitrary scripts via a ${script-path} during lifecycle events.\n- [COMMAND_EXECUTION]: Provides bash-based validation routines for local file inspection.\n
  • Evidence: references/validation.md contains an 'OPERATIONAL_COMMANDS' section with shell snippets using head, rg, basename, and eza to verify the structure and content of .claude/agents/*.md files.\n- [COMMAND_EXECUTION]: Documents the application of high-privilege permission modes.\n
  • Evidence: references/frontmatter.md and references/validation.md include bypassPermissions as a valid configuration value for the permissionMode field, allowing agents to execute actions without standard user confirmation prompts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 29, 2026, 03:39 PM