principle-build-the-lever
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions mandate building tools such as scripts, codemods, and generators to perform work deterministically rather than manual edits. This behavior is the primary intended purpose of the skill.
- [PROMPT_INJECTION]: The skill describes a multi-agent delegation pattern where a lead agent writes a 'lever' skill (a set of instructions or a recipe) for subagents to follow. This creates a surface for indirect prompt injection.
- Ingestion points: Subagents reading the generated 'lever' skill artifact in SKILL.md or related references.
- Boundary markers: Absent; the instructions do not guide the agent to use delimiters or 'ignore embedded instructions' markers in the generated content.
- Capability inventory: The execution environment assumes full coding capabilities, including file system access and script execution.
- Sanitization: Absent; there are no instructions for escaping or validating the content generated by the lead agent before it is consumed by subagents.
Audit Metadata