agent-byzantine-coordinator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines 'pre' and 'post' hooks in the YAML frontmatter that execute shell commands on the host environment during the skill lifecycle.
  • [INDIRECT_PROMPT_INJECTION]: The 'pre' hook script directly interpolates the $TASK environment variable into a shell command and a conditional check. This represents a vulnerability surface where malicious content in the task could attempt to escape the shell context and execute arbitrary commands.
  • Ingestion points: The $TASK variable used in SKILL.md hooks.
  • Boundary markers: None identified in the shell scripts to delimit untrusted data.
  • Capability inventory: Shell command execution via platform-native hooks.
  • Sanitization: No evidence of input validation or shell-escaping for the $TASK variable before its execution in the hook.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — agent-byzantine-coordinator