ai-coding-agents-remote-runtime
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for remote coding-agent runtimes that ingest untrusted data from an agent loop, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Untrusted agent output and tool results enter the local context via WebSocket, SSE, or ACP stdio transports (documented in references/local-ui-remote-execution-model.md).
- Boundary markers: The skill advocates for strict separation between transcript traffic and control traffic, using typed schemas to reduce instruction confusion (documented in SKILL.md and references/bridge-transport-and-permission-bridging.md).
- Capability inventory: The remote runtime facilitates the execution of arbitrary tools and commands, while the local controller provides approval routing and rendering capabilities.
- Sanitization: Implementation guidance recommends synthetic rendering for remote-only tools and structured error handling for unsupported control subtypes to maintain system stability (documented in SKILL.md).
Audit Metadata