gc-dispatch
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [COMMAND_EXECUTION]: The skill documents numerous
gcCLI commands (e.g.,gc sling,gc bd create,gc formula cook,gc convoy create) intended for agents to use for work dispatch, database management, and workflow coordination. - [DYNAMIC_EXECUTION]: The skill relies on "formulas" (v1 wisps and v2 workflows) which are dynamic templates that define execution steps. These formulas are instantiated at runtime and can execute complex DAGs (Directed Acyclic Graphs) of tasks, including git operations and code implementation.
- [INDIRECT_PROMPT_INJECTION]: The described workflow ingests "beads" which are work units defined by external input (e.g.,
gc bd create "fix the bug"). These beads serve as instructions for agents executing formulas, creating an inherent attack surface for indirect prompt injection. - Ingestion points: Bead IDs and their associated description/content fields provided at creation time.
- Boundary markers: The documentation does not specify the use of clear delimiters or instructions to ignore embedded prompts in bead content.
- Capability inventory: Formulas can perform file system writes, git branching/pushing, investigation reporting, and multi-agent coordination.
- Sanitization: No explicit sanitization or validation of bead content is mentioned in the dispatch instructions.
- [NO_CODE]: The skill is entirely comprised of markdown documentation and usage examples. It does not include separate script files, executables, or configuration files that run code independently.
Audit Metadata