team-builder

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions designed to subvert the agent's behavior.
  • Ingestion points: The skill reads markdown files located in ./agents/ and ~/.claude/agents/ (SKILL.md).
  • Boundary markers: The prompt template "{agent file content}\n\nTask: {task description}" lacks explicit delimiters (such as XML tags) or "ignore" instructions to separate the untrusted persona definition from the task input.
  • Capability inventory: The skill utilizes the Agent tool (subagent_type: "general-purpose") to execute the generated prompts.
  • Sanitization: There is no evidence of filtering, escaping, or validating the content of the markdown files before they are interpolated into the prompt and sent to the subagent tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — team-builder