agent-management
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill recommends using
npx ai-devkit@latest, which downloads and executes theai-devkitpackage from the NPM registry at runtime. While this is the primary tool for the skill, it introduces a dependency on external code fetched during execution. - [INDIRECT_PROMPT_INJECTION]: The
agent sendcommand enables an agent to delegate instructions to other agents, creating an attack surface where malicious input could be propagated if not properly sanitized. - Ingestion points: Instructions for
agent sendcan be derived from untrusted external data and passed via the CLI (SKILL.md). - Boundary markers: None present in the instructions to isolate forwarded content from agent instructions.
- Capability inventory: Uses the
ai-devkittool to start, stop, rename, and inspect agent processes. - Sanitization: The skill does not provide instructions for sanitizing content before sending it to other agents.
Audit Metadata