ai-coding-agents-remote-runtime

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for remote coding-agent runtimes that ingest untrusted data from an agent loop, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Untrusted agent output and tool results enter the local context via WebSocket, SSE, or ACP stdio transports (documented in references/local-ui-remote-execution-model.md).
  • Boundary markers: The skill advocates for strict separation between transcript traffic and control traffic, using typed schemas to reduce instruction confusion (documented in SKILL.md and references/bridge-transport-and-permission-bridging.md).
  • Capability inventory: The remote runtime facilitates the execution of arbitrary tools and commands, while the local controller provides approval routing and rendering capabilities.
  • Sanitization: Implementation guidance recommends synthetic rendering for remote-only tools and structured error handling for unsupported control subtypes to maintain system stability (documented in SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:06 PM
Security Audit — agent-trust-hub — ai-coding-agents-remote-runtime