team-builder
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions designed to subvert the agent's behavior.
- Ingestion points: The skill reads markdown files located in
./agents/and~/.claude/agents/(SKILL.md). - Boundary markers: The prompt template
"{agent file content}\n\nTask: {task description}"lacks explicit delimiters (such as XML tags) or "ignore" instructions to separate the untrusted persona definition from the task input. - Capability inventory: The skill utilizes the Agent tool (
subagent_type: "general-purpose") to execute the generated prompts. - Sanitization: There is no evidence of filtering, escaping, or validating the content of the markdown files before they are interpolated into the prompt and sent to the subagent tool.
Audit Metadata