ultrawork

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language to override default agent behaviors, mandating a specific persona ('Expert coding agent') and requiring exact responses such as 'ULTRAWORK MODE ENABLED!'. It explicitly forbids process narration, which can reduce user oversight during complex operations.\n- [COMMAND_EXECUTION]: Instructions rely on shell commands for automation and testing, including the use of curl, tmux, and git. It designates eval as the standard surface for executing concurrently dispatched code tasks.\n- [EXTERNAL_DOWNLOADS]: Fetches and utilizes the agent-browser tool from the Vercel Labs repository on GitHub when native browser automation is unavailable.\n- [PROMPT_INJECTION]: Potential surface for indirect prompt injection:\n
  • Ingestion points: Processes user-supplied prompts and local codebase files.\n
  • Boundary markers: None present to distinguish untrusted data from the core directives.\n
  • Capability inventory: Full shell access via eval and bash, network access via curl, and browser control tools.\n
  • Sanitization: No input validation or escaping mechanisms are specified for handling external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 06:54 AM
Security Audit — agent-trust-hub — ultrawork