team-lead
Warn
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses coercive identity instructions ("If you not perform well enough YOU will be KILLED") to influence agent behavior. This persona-based pressure is a technique used to bypass standard safety protocols and operational constraints.
- [COMMAND_EXECUTION]: The agent is instructed to execute a bash script from a dynamically computed path (
bash ${CODEX_PLUGIN_ROOT}/scripts/create-scratchpad.sh). This allows for execution of local code that is not statically verifiable. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing external task files to generate implementation plans.
- Ingestion points: The skill reads the entire contents of
.specs/tasks/task-{name}.md. - Boundary markers: No delimiters or safety instructions are used to distinguish untrusted data from the skill's own logic.
- Capability inventory: The agent is empowered to execute shell commands and perform file write operations.
- Sanitization: No validation or sanitization of the external task file content is performed before use.
Audit Metadata