dispatch-opencode

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates shell scripts (start-subagent.sh) from templates at runtime based on task parameters. This involves replacing placeholders in Jinja2-style templates using a Python helper script. The risk of command injection is effectively mitigated through the use of shlex.quote() on all user-supplied or agent-supplied variables before they are interpolated into the shell scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests plan YAMLs and prompt markdown files that could contain malicious instructions for subagents. The skill addresses this risk by implementing isolation through Git worktrees and providing a validation script (validate-run.sh) to check event logs and strip thinking blocks from outputs, allowing the orchestrating agent to verify subagent behavior.
  • [COMMAND_EXECUTION]: The skill performs various shell operations to manage the lifecycle of background tasks, including Git operations, process signaling, and invoking the opencode CLI. These operations are guarded by a dedicated verification script (verify-cwd.sh) that performs fail-closed path validation and a trunk guard that prevents subagents from writing directly to the main or master branches without an explicit override flag.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:19 PM
Security Audit — agent-trust-hub — dispatch-opencode