agent-army

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project codebase content which can contain untrusted data used to generate instructions for subordinate agents.\n
  • Ingestion points: Reads files identified during the Recon step (Step 3).\n
  • Boundary markers: Uses specific prompt templates for Layer 1 and Layer 2 agents to maintain operational scope.\n
  • Capability inventory: The skill can execute git commands, run project-defined build scripts, and spawn multiple agent instances.\n
  • Sanitization: No explicit sanitization or filtering of file content is defined before it is included in sub-agent prompts.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands to manage code state and verify modifications.\n
  • Evidence: Executes git commands (status, checkout, diff) for safety and runs the project's build command to confirm the integrity of the changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:02 PM
Security Audit — agent-trust-hub — agent-army