coupling-router

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local git commands through a Bun script (scripts/worktree-lease.ts) to verify repository status and manage worktree leases. The commands are hardcoded (e.g., git rev-parse --abbrev-ref HEAD) and are used to prevent merge conflicts between multiple agent sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves analyzing user-provided task breakdowns and skill stacks to produce a ROUTING_PLAN.md. This represents a vulnerability surface where instructions embedded in external task descriptions could attempt to influence the agent's delegation logic or the generated routing instructions.
  • Ingestion points: Task lists and candidate skill inventories processed in Step 1 and Step 3 of SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to isolate user-provided task content from the orchestration logic.
  • Capability inventory: The skill has the capability to execute shell commands (git via script), write files (ROUTING_PLAN.md), and dispatch sub-agents based on its analysis.
  • Sanitization: There is no evidence of input validation, escaping, or instruction-filtering for the ingested task descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — coupling-router