dym-setup-agent-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a shell command to index available skills using a local Python script: python3 ~/.claude/harness/fdk/tools/build-skill-search.py. This script is located in a hidden directory within the user's home folder.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests untrusted data and uses it to generate implementation plans and code changes, creating a vulnerability surface.
  • Ingestion points: Untrusted data enters the context via the /ingest command, which processes documents from the .llmwiki/raw/ directory, and during project onboarding where it analyzes existing codebase files.
  • Boundary markers: The skill documentation does not mention the use of delimiters or specific instructions to the agent to ignore embedded commands within the ingested content.
  • Capability inventory: The skill can execute a local Python script (build-skill-search.py) and perform Git operations such as commits, pushes, and PR creation via the /ship and /verify-before-commit commands.
  • Sanitization: No specific mechanisms for sanitizing, escaping, or validating the ingested content are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 06:22 AM