orchestration
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill spawns and manages subagents by executing "codex" and "claude" CLI tools through shell scripts such as "run-codex-agent.sh".
- [PRIVILEGE_ESCALATION]: To enable autonomous multi-agent orchestration, the skill explicitly uses flags that bypass user approval prompts and sandboxing. Specifically, it uses the "--dangerously-bypass-approvals-and-sandbox" flag for Codex and "--permission-prompts none" for the Claude CLI. While these are documented as necessary for the orchestration workflow, they remove standard human-in-the-loop safety checkpoints.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local companion skills, creating a potential vulnerability surface.
- Ingestion points: Reads "SKILL.md" files from "
/.claude/skills/" or "/.agents/skills/" (referenced in "SKILL.md"). - Boundary markers: Explicit delimiters or instructions to ignore embedded commands for the ingested skill content are absent.
- Capability inventory: Provides subagents with filesystem write and shell execution capabilities via "codex" and "claude" CLIs (managed in "run-codex-agent.sh").
- Sanitization: Validation or filtering of external skill content before interpolation is absent.
- [EXTERNAL_DOWNLOADS]: The skill uses the GitHub CLI ("gh") to monitor CI workflow status ("gh run list", "gh run watch") for modified repositories. These operations target a well-known service (GitHub) as part of a legitimate development workflow.
Audit Metadata