create-agent-adapter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building adapters that ingest and parse untrusted data from AI models to perform system-level actions.
  • Ingestion points: The server/parse.ts logic is designed to parse stdout and stderr streams from external agent processes (e.g., Claude Code, Codex).
  • Boundary markers: The skill recommends using structured parsing but does not provide specific implementation for instruction delimiters in the provided snippets.
  • Capability inventory: The adapters being documented have the capability to execute shell commands via runChildProcess and make network requests via fetch().
  • Sanitization: The documentation explicitly warns developers to treat agent output as untrusted, prohibits the use of eval(), and provides safe extraction helpers for data validation.
  • [COMMAND_EXECUTION]: The skill documents the use of the runChildProcess helper to spawn agent runtime processes. This functionality is the primary purpose of the adapter to bridge the orchestration layer with local CLI-based agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:46 PM
Security Audit — agent-trust-hub — create-agent-adapter