skills/hironow/skills/manager-loop/Gen Agent Trust Hub

manager-loop

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bundled Python script scripts/manager_loop_dashboard.py to manage the project's progress. The agent is instructed to run this script for initializing plans, ticking off completed tasks, and checking status. The script uses only the Python standard library and performs local file operations (reading/writing dashboard.html and a lock file).
  • [INDIRECT_PROMPT_INJECTION]: The skill consumes plan data that may be influenced by external input.
  • Ingestion points: The script reads manager-loop/plan.md to initialize the dashboard and parses dashboard.html to update state.
  • Boundary markers: Absent; the script relies on regex patterns (## Phase N:, - [ ]) to identify structural elements within the markdown and HTML files.
  • Capability inventory: The implementer agent is given broad autonomy, including shell command execution, file system access, and the ability to spawn sub-agents via the Agent tool.
  • Sanitization: The script employs html.escape when generating the HTML dashboard to prevent cross-site scripting (XSS) when the file is opened in a browser.
  • [DYNAMIC_EXECUTION]: A unit test file scripts/test_manager_loop_dashboard.py utilizes subprocess.run to verify the CLI functionality of the dashboard script. This is restricted to local testing of the bundled script and does not involve untrusted data or network-sourced code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 05:25 PM
Security Audit — agent-trust-hub — manager-loop