coding-agent
Warn
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands using the
bashtool, specifically promoting the use of the--yoloflag for the Codex CLI. This flag is explicitly described as disabling sandboxing and approvals, which facilitates autonomous execution of code changes without human-in-the-loop verification. Additionally, thebashtool documentation within the skill mentions anelevatedparameter for running commands on the host system instead of a sandbox. - [PROMPT_INJECTION]: The skill describes workflows for reviewing pull requests and fixing issues by cloning external GitHub repositories. This creates an indirect prompt injection surface where malicious instructions or adversarial patterns embedded in the external code or PR metadata could influence the behavior of the coding agent or the host agent.
- Ingestion points: External data enters the agent context via
git clone,gh pr checkout, andgit fetchoperations described in theSKILL.mdfiles. - Boundary markers: The instructions do not provide explicit boundary markers or warnings to the coding agents to treat the external repository content as untrusted data.
- Capability inventory: The skill has access to the
bashtool (with potential host access via theelevatedparameter) and theprocesstool for session manipulation (log, write, submit). - Sanitization: There is no evidence of sanitization, validation, or filtering of the external content before it is processed by the coding agents.
- [EXTERNAL_DOWNLOADS]: The skill instructions include commands to download and install software from external sources, such as
npm install -g @mariozechner/pi-coding-agentand cloning repositories from GitHub. While these target well-known services, they involve the download and execution of remote content.
Audit Metadata