skills/tenequm/skills/acpx-faq/Gen Agent Trust Hub

acpx-faq

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents workflows where autonomous subagents (Claude, Codex, Antigravity) ingest and process external, potentially untrusted data.
  • Ingestion points: Agents are instructed to read and act upon files provided via CLI flags or prompt text (e.g., brief.md, DESIGN.md) as seen in the acpx codex and acpx claude examples in SKILL.md.
  • Boundary markers: The provided recipes do not include specific delimiters or instructions to ignore malicious directives embedded within the processed files.
  • Capability inventory: The subagents described have significant capabilities, including reading and writing to the local filesystem (e.g., writing report.md) and potentially executing commands via their respective terminal or ACP capabilities.
  • Sanitization: No sanitization or validation mechanisms are described for the content of files processed by the agents.
  • [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands used to launch and control headless agents via the acpx utility. These agents are documented to run with broad permissions; specifically, the FAQ notes that the Claude adapter defaults to --allow-dangerously-skip-permissions, which bypasses standard Agent Client Protocol (ACP) safety prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 01:48 PM
Security Audit — agent-trust-hub — acpx-faq