ultrawork

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative directives to override default agent behavior, such as "MANDATORY: First user-visible line this turn MUST be exactly: ULTRAWORK MODE ENABLED!" and "Read the whole file and follow every rule in it for the rest of the task." It also creates an indirect prompt injection surface by requiring the agent to ingest and follow instructions from external skill files.- Ingestion points: The agent is instructed to read the body of loosely relevant skills (SKILL.md files) to gather context.- Boundary markers: No explicit instructions are provided to use delimiters or ignore embedded instructions when reading these skill bodies.- Capability inventory: The skill employs significant capabilities including network requests (curl), subagent spawning (multi_agent_v1.spawn_agent), and shell command execution.- Sanitization: No sanitization or filtering of external skill content is specified.- [EXTERNAL_DOWNLOADS]: The skill fetches the agent-browser utility from Vercel Labs' GitHub repository (https://github.com/vercel-labs/agent-browser) if native browser tools are not available.- [COMMAND_EXECUTION]: The instructions mandate the use of system tools such as curl, tmux, kill, and lsof for automated testing, evidence capture, and resource cleanup. It also references the execution of a local Node.js script (web-terminal-visual-qa.mjs) for terminal visualization.- [DATA_EXFILTRATION]: The skill uses curl -i to hit live endpoints and capture potentially sensitive response data (headers and body) as proof of work.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 12:43 PM
Security Audit — agent-trust-hub — ultrawork