omen
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill configuration explicitly instructs the agent to bypass security permission checks when executing external tools.
- Evidence: The reference documentation for the tri-engine failure recipe (
reference/tri-engine-failure.md) specifies that theagysub-agent must be executed using the commandagy -p "<prompt>" --dangerously-skip-permissions. This flag is explicitly intended to override safety and permission constraints in the target environment. - [DYNAMIC_EXECUTION]: The skill dynamically constructs and executes shell commands for sub-agents at runtime based on contextual input.
- Evidence: As detailed in
reference/tri-engine-failure.md, themultirecipe generates command strings forcodex execandagy -p. This runtime assembly of executable commands increases the risk of command injection and unverified system changes. - [COMMAND_EXECUTION]: The skill uses external command-line interfaces (
codex,agy) to perform its core logic. - Evidence: Both
SKILL.mdandreference/tri-engine-failure.mddescribe the dependency on these CLI tools for the parallel failure mode enumeration workflow. - [INDIRECT_PROMPT_INJECTION]: The skill functions as a vector for indirect prompt injection by ingesting untrusted artifacts and generating actionable instructions for other agents.
- Ingestion points: According to
SKILL.md, the skill ingests data from multiple sources includingScribe[unified]specs,Sparkfeature proposals, andMagistrategy documents. - Boundary markers: The skill does not implement boundary markers or instructions to disregard potential malicious prompts within the processed data.
- Capability inventory: The agent has the ability to execute shell commands and generate "Fix Prompts" for other agents (
Builder,Beacon,Triage, etc.), creating a chain where a malicious instruction in a spec could result in unauthorized actions by a downstream agent. - Sanitization: No sanitization process is described for the input data before it is incorporated into prompts for other agents.
- Evidence: The
fix-prompt-generationfeature described inSKILL.mdandreference/fix-prompt-generation.mdautomates the creation of prompts for other agents based on external documentation, without providing verification layers to prevent the propagation of malicious instructions.
Recommendations
- AI detected serious security threats
Audit Metadata