agent-manager-skill

Fail

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an external GitHub account (fractalmind-ai/agent-manager-skill) to obtain the necessary scripts for operation.
  • [REMOTE_CODE_EXECUTION]: The skill requires executing the downloaded Python scripts (agent-manager/scripts/main.py) on the local system, which results in the execution of unverified code from an external source.
  • [COMMAND_EXECUTION]: The primary function of the skill is to manage and run local CLI agents via tmux sessions, providing a mechanism for multi-process command execution.
  • [DATA_EXPOSURE]: The assign command allows for passing arbitrary instructions to agents through stdin. There is no evidence of input sanitization or boundary markers to prevent the agent from misinterpreting instructions embedded within the assigned tasks.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — agent-manager-skill