team-builder
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it loads and executes instructions from untrusted markdown files found in the file system.
- Ingestion points: The skill reads markdown files from project-local directories (
./agents/), global agent directories (~/.claude/agents/), and custom user-provided paths during the discovery phase. - Boundary markers: No boundary markers, XML delimiters, or 'ignore embedded instructions' warnings are used when interpolating file content into sub-agent prompts. The template used is
{agent file content}\n\nTask: {task description}. - Capability inventory: The skill utilizes the
Agenttool to spawn new processes with the loaded instructions, allowing personas defined in markdown to take control of sub-agent behavior. - Sanitization: There is no validation or filtering of the file content before it is processed and passed to the execution tool.
- [DATA_EXFILTRATION]: The skill is configured to scan and read from
~/.claude/agents/. This is an internal configuration directory used by the agent platform. Reading these files and passing their content to sub-agents could lead to the exposure of internal operational logic or instructions if a sub-agent's output is compromised or misdirected.
Audit Metadata