odyssey-ui

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Evidence: 1. Ingestion points: The skill reads project source code and configuration files via Glob and Read tools (SKILL.md). 2. Boundary markers: No explicit delimiters or instructions to ignore embedded content are used when passing file contents to sub-agents or external delegates. 3. Capability inventory: The skill has access to Write, Edit, Bash, and spawn_agents_on_csv tools. 4. Sanitization: No sanitization or validation of the ingested code is described before it influences agent actions.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute maestro delegation commands and orchestration logic. These commands interpolate project-specific variables such as target file paths and audit findings, which presents a risk of command injection if the project environment contains specially crafted file names or data.
  • [SAFE]: The core logic and tool usage are consistent with the stated purpose of UI auditing and optimization. No evidence of obfuscation, hardcoded credentials, or unauthorized data exfiltration was found in the instructions or scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 08:44 AM
Security Audit — agent-trust-hub — odyssey-ui