aiagent-command-router
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied slash commands (e.g.,
/start-0-1) to determine routing, which represents a potential ingestion surface for indirect prompt injection. - Ingestion points: User input strings matching command patterns defined in triggers (e.g.,
/start-). - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the prompt templates.
- Capability inventory: The skill delegates execution to other internal components (
aiagent-lesson-runnerandaiagent-utility-runner). - Sanitization: No explicit sanitization or validation logic is documented for the input strings before routing.
Audit Metadata