skills/simota/agent-skills/rally/Gen Agent Trust Hub

rally

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill orchestrates tasks by fanning them out to subagents, ingesting untrusted data from sources such as NEXUS_TO_RALLY_CONTEXT, SHERPA_TO_RALLY_HANDOFF, and direct user requests. This data is interpolated into subagent prompts without explicit sanitization or boundary delimiters that instruct the subagent to ignore embedded instructions. This creates a surface where malicious tasks could influence subagent behavior. Evidence: Ingestion points in SKILL.md (Workflow section) and reference/integration-patterns.md (Handoff templates); Boundary markers are absent for task content interpolation; Capability inventory includes spawning subagents with full tool access (Agent tool) and managing tasks; Sanitization of external task descriptions is not defined.
  • [COMMAND_EXECUTION]: The skill utilizes high-autonomy execution modes including bypassPermissions and dontAsk for spawned subagents. These modes allow agents to execute tools, including shell commands and file modifications, without requiring human-in-the-loop approval. While intended for parallel efficiency, this capability increases the potential impact of any injected malicious instructions. Evidence: reference/agent-teams-api-reference.md under teammate mode definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — rally