agent-communication

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use npx ai-devkit@latest, which downloads and executes the latest version of the ai-devkit package from the NPM registry at runtime.
  • [COMMAND_EXECUTION]: The instructions rely on executing shell commands (ai-devkit agent list, detail, send) to interact with other processes and agents.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a mechanism to read the recent context of other agents using ai-devkit agent detail --tail <n>. This creates an attack surface where an agent could inadvertently ingest and follow malicious instructions or adversarial data that was previously processed by another agent.
  • Ingestion points: ai-devkit agent detail output (SKILL.md).
  • Boundary markers: None specified in instructions to separate external agent context from the current agent's instructions.
  • Capability inventory: The agent can execute shell commands, read context, and send messages to other agents.
  • Sanitization: No explicit sanitization or validation of the retrieved agent context is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:15 PM
Security Audit — agent-trust-hub — agent-communication