aiagent-utility-runner

Warn

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill workflow explicitly directs the agent to execute local scripts and commands by resolving them from a manifest file (data/codex-command-manifest.json). It specifically mentions using a handler tool tools/codex_command_router.py to facilitate this execution.
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by instructing the agent to 'follow the source command instructions directly' from files found in .cursor/commands/. Since the agent's behavior is dictated by the content of these external files, malicious instructions embedded in those files would be executed without the oversight provided by the primary skill review.
  • Ingestion points: .cursor/commands/utility/*.md and .cursor/commands/*.md as specified in the workflow.
  • Boundary markers: None identified; instructions are followed 'directly'.
  • Capability inventory: Ability to execute local scripts and shell commands via tools/codex_command_router.py.
  • Sanitization: None specified for the content of the markdown command files.
  • [DATA_EXFILTRATION]: The skill includes triggers such as /setup-api-key and instructions for setup workflows. This indicates the skill is designed to handle sensitive credentials. While no explicit network exfiltration is visible in the SKILL.md, the capability to execute arbitrary local scripts in a context where API keys are being managed poses a high risk of credential exposure.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 05:58 AM
Security Audit — agent-trust-hub — aiagent-utility-runner