agent-builder

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a verification block designed to test the agent loading logic by executing a Python script via the command line interface.
  • [INDIRECT_PROMPT_INJECTION]: The skill architecture creates a surface for indirect prompt injection by defining agents with access to powerful tools like code_execution, file_read, and file_write.
  • Ingestion points: Sub-agents process user-provided queries and external data retrieved through RAG tools as defined in SKILL.md.
  • Boundary markers: The current system prompt templates do not include specific delimiters or instructions to ignore embedded commands in processed data.
  • Capability inventory: The registry.yaml file defines tools for filesystem access and arbitrary Python code execution for the Coder and Analyst agents.
  • Sanitization: The provided implementation does not include logic for sanitizing or validating inputs before they are processed by high-privilege tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:36 PM