figure-out-team

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external deliberation data from Slack channels and threads, which constitutes an ingestion surface for untrusted instructions from multiple participants.
  • Ingestion points: The [topic] and $ARGUMENTS fields in SKILL.md, along with asynchronous content from Slack deliberation participants.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the wrapper.
  • Capability inventory: The skill description indicates it can poll Slack users, gather evidence, and invoke other functional skills.
  • Sanitization: There is no evidence of input validation or sanitization before external data is passed to the orchestration logic.
  • [COMMAND_EXECUTION]: The skill dynamically interpolates user-provided arguments into a call to another skill.
  • Evidence: Invoke the figure-out skill with: "$ARGUMENTS --team" directly maps user input into a command template, which could be exploited if the underlying execution environment does not properly escape shell characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:34 PM
Security Audit — agent-trust-hub — figure-out-team