dual-ai
Warn
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill generates and executes platform-specific launcher scripts (.sh for Linux/macOS, .ps1 for Windows) at runtime to spawn external AI CLI sessions (claude and codex).
- [COMMAND_EXECUTION]: The skill dynamically constructs shell commands and script files using repository paths and user-provided inputs before executing them via system tools like pwsh, open, or x-terminal-emulator.
- [COMMAND_EXECUTION]: The skill executes a bundled Node.js script scripts/dual-ai-runner.mjs to orchestrate sessions in orchestrated mode.
- [PROMPT_INJECTION]: The skill processes untrusted user input that is passed to external agents with high capabilities. Ingestion points: The $ARGUMENTS variable is captured in SKILL.md and used to populate prompt files for external sessions. Boundary markers: None identified; user input is written verbatim to prompt-claude.txt and prompt-codex.txt. Capability inventory: The skill spawns external processes with security permissions disabled (--dangerously-skip-permissions, --dangerously-bypass-approvals-and-sandbox) and high reasoning effort. Sanitization: Absent; the skill documentation explicitly states to treat prompt values as opaque literals without reformatting or expansion.
- [COMMAND_EXECUTION]: The skill uses chmod +x on dynamically generated shell scripts to make them executable by the system.
Audit Metadata