agent-manager-skill
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from a third-party source:
https://github.com/fractalmind-ai/agent-manager-skill.git. This source is not recognized as a trusted organization or well-known service. - [REMOTE_CODE_EXECUTION]: Instructs the user to execute code (
python3 agent-manager/scripts/main.py) directly from the downloaded external repository. - [PERSISTENCE]: The skill description mentions "cron-friendly scheduling" and "recurring agent work," suggesting functionality for establishing persistent background processes on the host system.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The
assigncommand inSKILL.mdaccepts arbitrary multi-line text input using anEOFblock. - Boundary markers: No delimiters or safety instructions are provided to the agent for handling the content within the
EOFblock. - Capability inventory: The skill can execute Python scripts and manage background tmux sessions.
- Sanitization: There is no evidence of input validation or sanitization for the tasks assigned to the agents.
- [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary agent commands and tasks within local tmux sessions.
Recommendations
- AI detected serious security threats
Audit Metadata