dym-setup-agent-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a shell command to index available skills using a local Python script:
python3 ~/.claude/harness/fdk/tools/build-skill-search.py. This script is located in a hidden directory within the user's home folder. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests untrusted data and uses it to generate implementation plans and code changes, creating a vulnerability surface.
- Ingestion points: Untrusted data enters the context via the
/ingestcommand, which processes documents from the.llmwiki/raw/directory, and during project onboarding where it analyzes existing codebase files. - Boundary markers: The skill documentation does not mention the use of delimiters or specific instructions to the agent to ignore embedded commands within the ingested content.
- Capability inventory: The skill can execute a local Python script (
build-skill-search.py) and perform Git operations such as commits, pushes, and PR creation via the/shipand/verify-before-commitcommands. - Sanitization: No specific mechanisms for sanitizing, escaping, or validating the ingested content are described.
Audit Metadata