orchestration

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill spawns and manages subagents by executing "codex" and "claude" CLI tools through shell scripts such as "run-codex-agent.sh".
  • [PRIVILEGE_ESCALATION]: To enable autonomous multi-agent orchestration, the skill explicitly uses flags that bypass user approval prompts and sandboxing. Specifically, it uses the "--dangerously-bypass-approvals-and-sandbox" flag for Codex and "--permission-prompts none" for the Claude CLI. While these are documented as necessary for the orchestration workflow, they remove standard human-in-the-loop safety checkpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from local companion skills, creating a potential vulnerability surface.
  • Ingestion points: Reads "SKILL.md" files from "/.claude/skills/" or "/.agents/skills/" (referenced in "SKILL.md").
  • Boundary markers: Explicit delimiters or instructions to ignore embedded commands for the ingested skill content are absent.
  • Capability inventory: Provides subagents with filesystem write and shell execution capabilities via "codex" and "claude" CLIs (managed in "run-codex-agent.sh").
  • Sanitization: Validation or filtering of external skill content before interpolation is absent.
  • [EXTERNAL_DOWNLOADS]: The skill uses the GitHub CLI ("gh") to monitor CI workflow status ("gh run list", "gh run watch") for modified repositories. These operations target a well-known service (GitHub) as part of a legitimate development workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 10:18 PM