agent-builder

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input via agent_build, agent_loop, and agent_message (e.g., role, goal, custom_instructions, message) and interpolates it directly into markdown files (PROMPT.md) or message queues (inbox.json) that govern the behavior of sub-agents.
  • Ingestion points: The role, goal, custom_instructions, and output_schema fields in the agent_build tool; the message field in the agent_message tool.
  • Boundary markers: The sub-agent prompts lack explicit boundary markers or instructions to disregard potentially malicious commands embedded within the user-provided role or goal descriptions.
  • Capability inventory: Sub-agents have access to platform tools like sessions_spawn and are instructed by the general-guide.md to use bash for deterministic operations.
  • Sanitization: User inputs are not sanitized or escaped before being written into prompt templates.
  • [DYNAMIC_EXECUTION]: The skill generates Python scripts by performing string replacement on templates (templates/daemon_run.py and templates/scheduled_run.py). These scripts are then written to the tasks/ directory and executed by the platform's scheduler.
  • Evidence: tools.py implements logic in AgentBuildTool.execute to overwrite platform-generated task scripts with custom logic defined in the skill's template directory.
  • [PERSISTENCE]: The agent_build tool registers recurring cron or interval tasks using the scheduled_task tool, creating persistent execution cycles for micro-agents.
  • Evidence: The tool calls ctx.call_tool("scheduled_task", action="register", ...) to set up background daemons that poll for messages or execute tasks periodically.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — agent-builder