agent-builder
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input via
agent_build,agent_loop, andagent_message(e.g.,role,goal,custom_instructions,message) and interpolates it directly into markdown files (PROMPT.md) or message queues (inbox.json) that govern the behavior of sub-agents. - Ingestion points: The
role,goal,custom_instructions, andoutput_schemafields in theagent_buildtool; themessagefield in theagent_messagetool. - Boundary markers: The sub-agent prompts lack explicit boundary markers or instructions to disregard potentially malicious commands embedded within the user-provided role or goal descriptions.
- Capability inventory: Sub-agents have access to platform tools like
sessions_spawnand are instructed by thegeneral-guide.mdto usebashfor deterministic operations. - Sanitization: User inputs are not sanitized or escaped before being written into prompt templates.
- [DYNAMIC_EXECUTION]: The skill generates Python scripts by performing string replacement on templates (
templates/daemon_run.pyandtemplates/scheduled_run.py). These scripts are then written to thetasks/directory and executed by the platform's scheduler. - Evidence:
tools.pyimplements logic inAgentBuildTool.executeto overwrite platform-generated task scripts with custom logic defined in the skill's template directory. - [PERSISTENCE]: The
agent_buildtool registers recurring cron or interval tasks using thescheduled_tasktool, creating persistent execution cycles for micro-agents. - Evidence: The tool calls
ctx.call_tool("scheduled_task", action="register", ...)to set up background daemons that poll for messages or execute tasks periodically.
Audit Metadata