user-proxy
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to evaluate plans and work output generated by other agents. This creates an ingestion surface for potentially untrusted data. The skill lacks explicit boundary markers or sanitization for this external content, which is a standard risk for reviewer-type agents. The impact is minimized by the skill's restricted output format (APPROVE/FLAG).\n- [EXTERNAL_DOWNLOADS]: The skill instructions in
AGENTS.mdguide the agent to usenpx compose-agentsmdfor rule regeneration. This involves fetching and executing a Node.js package. The referenced package is a known resource within the vendor's (metyatech) development workflow.
Audit Metadata