team-builder
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted agent definition files and user task descriptions, which are then interpolated into sub-agent prompts without clear boundaries or sanitization. Ingestion points: Reads agent markdown files from the local project directory (
./agents/) and the global user agent directory (~/.claude/agents/), as well as user-provided task descriptions. Boundary markers: Absent. Instructions are concatenated directly:{agent file content}\n\nTask: {task description}. Capability inventory: Spawns parallel sub-agents using theAgenttool withsubagent_type: 'general-purpose', providing a broad range of capabilities to potentially hijacked sub-agents. Sanitization: None. The skill does not escape or validate the content of the markdown files or the task description before passing them to the sub-agent tool. - [COMMAND_EXECUTION]: The skill instructs the agent to run the
claude agentsCLI command to discover available agents. While this is a platform-specific discovery command, it involves executing shell commands based on instructions in the skill.
Audit Metadata