agent-manager-skill

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from a third-party source: https://github.com/fractalmind-ai/agent-manager-skill.git. This source is not recognized as a trusted organization or well-known service.
  • [REMOTE_CODE_EXECUTION]: Instructs the user to execute code (python3 agent-manager/scripts/main.py) directly from the downloaded external repository.
  • [PERSISTENCE]: The skill description mentions "cron-friendly scheduling" and "recurring agent work," suggesting functionality for establishing persistent background processes on the host system.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The assign command in SKILL.md accepts arbitrary multi-line text input using an EOF block.
  • Boundary markers: No delimiters or safety instructions are provided to the agent for handling the content within the EOF block.
  • Capability inventory: The skill can execute Python scripts and manage background tmux sessions.
  • Sanitization: There is no evidence of input validation or sanitization for the tasks assigned to the agents.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary agent commands and tasks within local tmux sessions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — agent-manager-skill