team-builder
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill discovers and reads markdown files from the local filesystem (
./agents/and~/.claude/agents/) to define agent personas. This content is then directly interpolated into the prompt for theAgenttool, creating a vulnerability surface where a malicious markdown file could hijack the subagent's behavior. - Ingestion points: Markdown files located in the project's
agents/folder and the global~/.claude/agents/directory. - Boundary markers: The skill lacks explicit boundary markers or 'ignore embedded instructions' directives when constructing the subagent prompt:
"{agent file content}\n\nTask: {task description}". - Capability inventory: The skill uses the
Agenttool to spawn subagents with context derived from external files. - Sanitization: No sanitization, filtering, or validation of the ingested markdown content is performed before it is sent to the subagent.
- [COMMAND_EXECUTION]: The skill relies on executing the
claude agentscommand to discover available agents. While this is a standard CLI command for the intended platform, it represents an automated command execution pattern based on the skill's instructions.
Audit Metadata