skills/delorenj/skills/agent-team-kit/Gen Agent Trust Hub

agent-team-kit

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of documentation, process templates, and configuration drafts. It does not include any executable scripts (Python, JavaScript, shell) or binaries, precluding traditional code-based attack vectors.\n- [NO_CODE]: No source code was detected in the skill files; the functionality is delivered purely through instructional Markdown templates and metadata configuration.\n- [PROMPT_INJECTION]: The framework design establishes an indirect prompt injection surface. The 'Scout' role is directed to ingest untrusted data from external sources (e.g., user feedback, community channels) into the shared OPPORTUNITIES.md file. This data is subsequently processed by the 'Rhythm' role for triage and eventually assigned to execution agents as task descriptions. The provided templates do not include explicit boundary markers, sanitization instructions, or 'ignore embedded instructions' warnings to mitigate potential malicious instructions hidden in this ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:16 AM
Security Audit — agent-trust-hub — agent-team-kit