agentica-claude-proxy
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents a REPL (Read-Eval-Print Loop) integration pattern where the agent is instructed to return Python code blocks (using a
returnstatement) that are subsequently extracted and executed by a parser. This mechanism executes code generated by the LLM at runtime. - [INDIRECT_PROMPT_INJECTION]: The integration architecture creates an ingestion surface where data fetched via tools (like
ReadorBash) is fed back into the agent context. The skill lack instructions for boundary markers or sanitization of this external content, which could allow instructions embedded in processed files to influence agent behavior. - [COMMAND_EXECUTION]: The documentation provides multiple shell command examples for orchestrating system processes, including starting proxies and servers using
uv run, performing network health checks viacurl, and inspecting logs usingcat. - [PROMPT_INJECTION]: The 'Anti-Hallucination Prompt Engineering' section contains instructional overrides and emphatic directives (e.g., 'STOP AND READ THIS CAREFULLY', 'DO NOT skip the tool invocation') intended to force the agent to prioritize specific behaviors over its standard processing logic.
Audit Metadata