agent-byzantine-coordinator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines 'pre' and 'post' hooks in the YAML frontmatter that execute shell commands on the host environment during the skill lifecycle.
- [INDIRECT_PROMPT_INJECTION]: The 'pre' hook script directly interpolates the $TASK environment variable into a shell command and a conditional check. This represents a vulnerability surface where malicious content in the task could attempt to escape the shell context and execute arbitrary commands.
- Ingestion points: The $TASK variable used in SKILL.md hooks.
- Boundary markers: None identified in the shell scripts to delimit untrusted data.
- Capability inventory: Shell command execution via platform-native hooks.
- Sanitization: No evidence of input validation or shell-escaping for the $TASK variable before its execution in the hook.
Audit Metadata