team-builder

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill discovers and reads markdown files from the local filesystem (./agents/ and ~/.claude/agents/) to define agent personas. This content is then directly interpolated into the prompt for the Agent tool, creating a vulnerability surface where a malicious markdown file could hijack the subagent's behavior.
  • Ingestion points: Markdown files located in the project's agents/ folder and the global ~/.claude/agents/ directory.
  • Boundary markers: The skill lacks explicit boundary markers or 'ignore embedded instructions' directives when constructing the subagent prompt: "{agent file content}\n\nTask: {task description}".
  • Capability inventory: The skill uses the Agent tool to spawn subagents with context derived from external files.
  • Sanitization: No sanitization, filtering, or validation of the ingested markdown content is performed before it is sent to the subagent.
  • [COMMAND_EXECUTION]: The skill relies on executing the claude agents command to discover available agents. While this is a standard CLI command for the intended platform, it represents an automated command execution pattern based on the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — team-builder