field-audit
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill determines the location of its core ledger tool,
field.py, at runtime using afindcommand and subsequently executes it usingpython3. This constitutes execution of a script from a dynamically computed path. - Evidence:
FIELD_HANDLER_PANE=$SELF python3 <agent_dir>/field.py audit --include-looseandpython3 <agent_dir>/field.py close "<name>". - [INDIRECT_PROMPT_INJECTION]: The skill reads and evaluates output from other agents, using that data to decide whether to acknowledge work, prompt the agent for more details, or close the execution pane. This introduces a risk where malicious or unexpected content in an agent's output could influence the auditor's actions.
- Ingestion points:
herdr agent read "<name>" --source recent --lines 80inSKILL.md. - Boundary markers: None identified in the prompt interpolation.
- Capability inventory: Ability to close panes, remove git worktrees, and prompt other agents via
herdrandfield.py. - Sanitization: None identified; the skill relies on the agent's judgment of the unverified output.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to the agent to suggest an external installation command to the user if the required suite is not found. The command targets a vendor-owned resource on a well-known service (NPM).
- Evidence:
npx skills add gregbarbosa/skills -s '*' -g -y
Audit Metadata