skills/simota/agent-skills/magi/Gen Agent Trust Hub

magi

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's 'Engine Mode' and 'multi' recipe rely on executing shell commands via external CLI tools. Specifically, the 'reference/engine-deliberation-guide.md' and 'reference/tri-engine-deliberate.md' files instruct the agent to use the following commands: 'codex exec --full-auto "{prompt}"' and 'agy -p "{prompt}" --dangerously-skip-permissions --log-file '. The use of the '--dangerously-skip-permissions' flag is a direct instruction to bypass security and permission models of the underlying tool.
  • [DYNAMIC_EXECUTION]: The skill dynamically constructs prompts based on untrusted user-provided context and executes these prompts as command-line arguments to external engines. This represents a risk of command injection if the user input is not properly sanitized before being passed to the shell-executing CLI tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it ingests data from multiple external sources (users, other agents like Nexus/Scribe) and has high-privilege shell execution capabilities.
  • Ingestion points: User input via 'Decision Request' and input blocks from other agents (e.g., ATLAS_TO_MAGI, NEXUS_TO_MAGI).
  • Boundary markers: The skill uses a structured 'FRAME' phase to define context, but there are no explicit 'ignore embedded instructions' warnings for the sub-engine prompts.
  • Capability inventory: Shell execution of CLI tools with permission bypass flags.
  • Sanitization: The instructions do not define any sanitization or escaping protocols for external content before it is interpolated into the prompts for the external engines.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — magi