create-agent-adapter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building adapters that ingest and parse untrusted data from AI models to perform system-level actions.
- Ingestion points: The
server/parse.tslogic is designed to parse stdout and stderr streams from external agent processes (e.g., Claude Code, Codex). - Boundary markers: The skill recommends using structured parsing but does not provide specific implementation for instruction delimiters in the provided snippets.
- Capability inventory: The adapters being documented have the capability to execute shell commands via
runChildProcessand make network requests viafetch(). - Sanitization: The documentation explicitly warns developers to treat agent output as untrusted, prohibits the use of
eval(), and provides safe extraction helpers for data validation. - [COMMAND_EXECUTION]: The skill documents the use of the
runChildProcesshelper to spawn agent runtime processes. This functionality is the primary purpose of the adapter to bridge the orchestration layer with local CLI-based agents.
Audit Metadata