skills/johngrimes/mojoflow/build/Gen Agent Trust Hub

build

Warn

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs a reviewer subagent to build and execute generated code using Bash. This involves running implementation logic that was dynamically created by other agents at runtime, which represents a significant security boundary as it permits the execution of arbitrary, AI-generated scripts within the host environment.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a 'spec bundle' (including spec.md, plan.md, and tasks.md) and incorporates it into the context for a reviewer subagent. The subagent possesses broad capabilities, including browser control and repository management. A lack of explicit boundary markers or sanitization for these input files could allow instructions embedded within the specifications to influence the subagent's judgment or actions. Ingestion points: spec.md, plan.md, tasks.md, data-model.md, research.md, quickstart.md. Boundary markers: Absent. Capability inventory: Bash execution, browser control via agent-browser, and GitHub management via github-cli. Sanitization: Absent content filtering for specification files.- [COMMAND_EXECUTION]: The skill performs shell-level operations such as git rev-parse and manages external resources via the github-cli skill. These commands interact directly with the underlying operating system and remote version control systems, representing a functional attack surface if the inputs or generated code are manipulated.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 29, 2026, 11:04 PM
Security Audit — agent-trust-hub — build