user-proxy

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to evaluate plans and work output generated by other agents. This creates an ingestion surface for potentially untrusted data. The skill lacks explicit boundary markers or sanitization for this external content, which is a standard risk for reviewer-type agents. The impact is minimized by the skill's restricted output format (APPROVE/FLAG).\n- [EXTERNAL_DOWNLOADS]: The skill instructions in AGENTS.md guide the agent to use npx compose-agentsmd for rule regeneration. This involves fetching and executing a Node.js package. The referenced package is a known resource within the vendor's (metyatech) development workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 07:53 AM
Security Audit — agent-trust-hub — user-proxy