manager-loop
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bundled Python script
scripts/manager_loop_dashboard.pyto manage the project's progress. The agent is instructed to run this script for initializing plans, ticking off completed tasks, and checking status. The script uses only the Python standard library and performs local file operations (reading/writingdashboard.htmland a lock file). - [INDIRECT_PROMPT_INJECTION]: The skill consumes plan data that may be influenced by external input.
- Ingestion points: The script reads
manager-loop/plan.mdto initialize the dashboard and parsesdashboard.htmlto update state. - Boundary markers: Absent; the script relies on regex patterns (
## Phase N:,- [ ]) to identify structural elements within the markdown and HTML files. - Capability inventory: The implementer agent is given broad autonomy, including shell command execution, file system access, and the ability to spawn sub-agents via the
Agenttool. - Sanitization: The script employs
html.escapewhen generating the HTML dashboard to prevent cross-site scripting (XSS) when the file is opened in a browser. - [DYNAMIC_EXECUTION]: A unit test file
scripts/test_manager_loop_dashboard.pyutilizessubprocess.runto verify the CLI functionality of the dashboard script. This is restricted to local testing of the bundled script and does not involve untrusted data or network-sourced code.
Audit Metadata