agent-builder
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a verification block designed to test the agent loading logic by executing a Python script via the command line interface.
- [INDIRECT_PROMPT_INJECTION]: The skill architecture creates a surface for indirect prompt injection by defining agents with access to powerful tools like
code_execution,file_read, andfile_write. - Ingestion points: Sub-agents process user-provided queries and external data retrieved through RAG tools as defined in
SKILL.md. - Boundary markers: The current system prompt templates do not include specific delimiters or instructions to ignore embedded commands in processed data.
- Capability inventory: The
registry.yamlfile defines tools for filesystem access and arbitrary Python code execution for the Coder and Analyst agents. - Sanitization: The provided implementation does not include logic for sanitizing or validating inputs before they are processed by high-privilege tools.
Audit Metadata