skills/richardbray/skills/delegate/Gen Agent Trust Hub

delegate

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill transmits project context, file paths, and code to external AI services including xAI (Grok) and OpenCode (GLM). These providers are third-party entities not included in the trusted vendor list, representing a risk for sensitive data exposure.
  • [REMOTE_CODE_EXECUTION]: The orchestration workflow instructs the agent to execute code generated by external sub-models to verify its correctness. This pattern results in the execution of unverified code derived from remote, untrusted sources.
  • [COMMAND_EXECUTION]: Integration with the WezTerm CLI allows the agent to send text and commands to terminal panes. This capability can be used to execute arbitrary shell commands, potentially bypassing the skill's tool restrictions by proxying execution through a persistent terminal session.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external AI models and terminal buffer scrapes, creating an attack surface where a compromised sub-model could influence the agent's next steps. Ingestion points include results from courier agents and data retrieved via WezTerm. While status prefixes are used as boundary markers, the skill lacks explicit sanitization or sandboxing of the generated code before the agent attempts to execute it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:20 AM
Security Audit — agent-trust-hub — delegate