coupling-router
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local git commands through a Bun script (
scripts/worktree-lease.ts) to verify repository status and manage worktree leases. The commands are hardcoded (e.g.,git rev-parse --abbrev-ref HEAD) and are used to prevent merge conflicts between multiple agent sessions. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves analyzing user-provided task breakdowns and skill stacks to produce a
ROUTING_PLAN.md. This represents a vulnerability surface where instructions embedded in external task descriptions could attempt to influence the agent's delegation logic or the generated routing instructions. - Ingestion points: Task lists and candidate skill inventories processed in Step 1 and Step 3 of
SKILL.md. - Boundary markers: The instructions do not specify any delimiters or safety markers to isolate user-provided task content from the orchestration logic.
- Capability inventory: The skill has the capability to execute shell commands (
gitvia script), write files (ROUTING_PLAN.md), and dispatch sub-agents based on its analysis. - Sanitization: There is no evidence of input validation, escaping, or instruction-filtering for the ingested task descriptions.
Audit Metadata