team-builder

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it loads and executes instructions from untrusted markdown files found in the file system.
  • Ingestion points: The skill reads markdown files from project-local directories (./agents/), global agent directories (~/.claude/agents/), and custom user-provided paths during the discovery phase.
  • Boundary markers: No boundary markers, XML delimiters, or 'ignore embedded instructions' warnings are used when interpolating file content into sub-agent prompts. The template used is {agent file content}\n\nTask: {task description}.
  • Capability inventory: The skill utilizes the Agent tool to spawn new processes with the loaded instructions, allowing personas defined in markdown to take control of sub-agent behavior.
  • Sanitization: There is no validation or filtering of the file content before it is processed and passed to the execution tool.
  • [DATA_EXFILTRATION]: The skill is configured to scan and read from ~/.claude/agents/. This is an internal configuration directory used by the agent platform. Reading these files and passing their content to sub-agents could lead to the exposure of internal operational logic or instructions if a sub-agent's output is compromised or misdirected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:43 AM
Security Audit — agent-trust-hub — team-builder