skills/duc01226/easyplatform/dual-ai/Gen Agent Trust Hub

dual-ai

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and executes platform-specific launcher scripts (.sh for Linux/macOS, .ps1 for Windows) at runtime to spawn external AI CLI sessions (claude and codex).
  • [COMMAND_EXECUTION]: The skill dynamically constructs shell commands and script files using repository paths and user-provided inputs before executing them via system tools like pwsh, open, or x-terminal-emulator.
  • [COMMAND_EXECUTION]: The skill executes a bundled Node.js script scripts/dual-ai-runner.mjs to orchestrate sessions in orchestrated mode.
  • [PROMPT_INJECTION]: The skill processes untrusted user input that is passed to external agents with high capabilities. Ingestion points: The $ARGUMENTS variable is captured in SKILL.md and used to populate prompt files for external sessions. Boundary markers: None identified; user input is written verbatim to prompt-claude.txt and prompt-codex.txt. Capability inventory: The skill spawns external processes with security permissions disabled (--dangerously-skip-permissions, --dangerously-bypass-approvals-and-sandbox) and high reasoning effort. Sanitization: Absent; the skill documentation explicitly states to treat prompt values as opaque literals without reformatting or expansion.
  • [COMMAND_EXECUTION]: The skill uses chmod +x on dynamically generated shell scripts to make them executable by the system.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — dual-ai