rally
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill orchestrates tasks by fanning them out to subagents, ingesting untrusted data from sources such as
NEXUS_TO_RALLY_CONTEXT,SHERPA_TO_RALLY_HANDOFF, and direct user requests. This data is interpolated into subagent prompts without explicit sanitization or boundary delimiters that instruct the subagent to ignore embedded instructions. This creates a surface where malicious tasks could influence subagent behavior. Evidence: Ingestion points inSKILL.md(Workflow section) andreference/integration-patterns.md(Handoff templates); Boundary markers are absent for task content interpolation; Capability inventory includes spawning subagents with full tool access (Agenttool) and managing tasks; Sanitization of external task descriptions is not defined. - [COMMAND_EXECUTION]: The skill utilizes high-autonomy execution modes including
bypassPermissionsanddontAskfor spawned subagents. These modes allow agents to execute tools, including shell commands and file modifications, without requiring human-in-the-loop approval. While intended for parallel efficiency, this capability increases the potential impact of any injected malicious instructions. Evidence:reference/agent-teams-api-reference.mdunder teammatemodedefinitions.
Audit Metadata