ray-multimodel
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to invoke external CLI tools such as grok, claude, and codex via shell commands. It recommends security-hardened configurations, including flags like --permission-mode plan and --no-subagents, to restrict the sub-models' execution capabilities.\n- [DATA_EXFILTRATION]: The skill's primary function involves transmitting project context and code to external AI providers. To manage this risk, it enforces explicit 'Isolation Gates' and data classification policies that strictly prohibit the sharing of sensitive materials such as credentials, tokens, or private configuration files.\n- [PROMPT_INJECTION]: The skill processes structured reports generated by external models, creating a surface for indirect prompt injection. The skill mitigates this through a mandatory evidence chain that requires the master agent to independently verify all artifacts and execution results rather than relying on the sub-model's self-reported status.
Audit Metadata