ultrawork
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative language to override default agent behaviors, mandating a specific persona ('Expert coding agent') and requiring exact responses such as 'ULTRAWORK MODE ENABLED!'. It explicitly forbids process narration, which can reduce user oversight during complex operations.\n- [COMMAND_EXECUTION]: Instructions rely on shell commands for automation and testing, including the use of
curl,tmux, andgit. It designatesevalas the standard surface for executing concurrently dispatched code tasks.\n- [EXTERNAL_DOWNLOADS]: Fetches and utilizes theagent-browsertool from the Vercel Labs repository on GitHub when native browser automation is unavailable.\n- [PROMPT_INJECTION]: Potential surface for indirect prompt injection:\n - Ingestion points: Processes user-supplied prompts and local codebase files.\n
- Boundary markers: None present to distinguish untrusted data from the core directives.\n
- Capability inventory: Full shell access via
evalandbash, network access viacurl, and browser control tools.\n - Sanitization: No input validation or escaping mechanisms are specified for handling external data.
Audit Metadata