skills/gregbarbosa/skills/thread/Gen Agent Trust Hub

thread

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to construct and execute shell commands using the herdr CLI, specifically when prompting spawned agents. The user's request is interpolated directly into the herdr agent prompt command string. Because the instructions do not explicitly mandate escaping or sanitizing this input, a user could craft a message containing shell metacharacters (such as double quotes, semicolons, or backticks) to execute arbitrary commands on the host system via the agent's shell tool.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a callback system where a spawned agent notifies the calling agent upon task completion. This notification summary is delivered back to the caller's pane using the agent prompt tool. This creates a risk where a spawned agent, if compromised by malicious data it processes, could inject instructions into the original agent's context through the notification message.\n
  • Ingestion points: User-provided <request> strings derived from the initial message in SKILL.md.\n
  • Boundary markers: No explicit delimiters or isolation markers are defined to separate the user request from the agent's control logic in SKILL.md.\n
  • Capability inventory: herdr agent start, herdr agent prompt, herdr worktree create, and herdr tab create commands are all executed based on logic in SKILL.md.\n
  • Sanitization: No instructions for escaping or validating external content are provided for either the initial request or the completion summary.\n- [DYNAMIC_EXECUTION]: The skill uses a Python one-liner to parse JSON data at runtime to extract pane identifiers. While used for a legitimate utility purpose, it represents the dynamic generation and execution of script code to handle command output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 02:20 PM