figure-out-team
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external deliberation data from Slack channels and threads, which constitutes an ingestion surface for untrusted instructions from multiple participants.
- Ingestion points: The [topic] and $ARGUMENTS fields in SKILL.md, along with asynchronous content from Slack deliberation participants.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the wrapper.
- Capability inventory: The skill description indicates it can poll Slack users, gather evidence, and invoke other functional skills.
- Sanitization: There is no evidence of input validation or sanitization before external data is passed to the orchestration logic.
- [COMMAND_EXECUTION]: The skill dynamically interpolates user-provided arguments into a call to another skill.
- Evidence: Invoke the figure-out skill with: "$ARGUMENTS --team" directly maps user input into a command template, which could be exploited if the underlying execution environment does not properly escape shell characters.
Audit Metadata