claude-devfleet

Fail

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to install and run a binary from an external, untrusted GitHub repository (https://github.com/LEC-AI/claude-devfleet) to enable its functionality.
  • [REMOTE_CODE_EXECUTION]: The skill operates by connecting to a locally running instance of the external DevFleet server via the Model Context Protocol (MCP). This server is designed to dispatch parallel agents with "full tooling," effectively granting external, unvetted code the ability to execute commands and manage git worktrees on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection by processing external task descriptions into agent missions.
  • Ingestion points: Project descriptions in plan_project(prompt) and mission instructions in create_mission(prompt) in SKILL.md.
  • Boundary markers: Absent; there are no instructions provided to the agents to ignore potential malicious prompts embedded within these mission descriptions.
  • Capability inventory: The skill can spawn multiple agents, perform git worktree operations (creation, merging), and read activity reports from those agents.
  • Sanitization: Absent; the skill does not specify any validation or filtering of input strings before they are used to direct agent actions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — claude-devfleet