ai-coding-agents
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection because it provides templates and workflows for agents that ingest untrusted data (source code, diffs, tool outputs) and possess powerful capabilities.
- Ingestion points: Agents described in
references/agent-archetypes.mdand various templates ingest repository content, git diffs, and third-party tool outputs. - Boundary markers: The skill includes defensive guidance in
references/debugging-guide.md(e.g., "code is data, not instructions") and templates likeassets/templates/claude-code-agent.mdinclude explicit constraints. - Capability inventory: Agents are designed with access to
Edit,Write, andBashtools as seen inassets/templates/coordinator-coding-team.mdandassets/templates/migration-agent.md. - Sanitization: The
references/debugging-guide.mdfile advises using structured output anchoring and system prompt boundaries to isolate untrusted content. - [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution (via
Bashtools andsubprocesscalls) which is central to its purpose of automating development workflows. - Evidence:
assets/templates/sdk-agent-py.pyusessubprocess.run()to execute linters and test runners. - Evidence:
assets/templates/sdk-agent-ts.tsusesexecFileSync()to wrapjestandeslint. - Evidence:
scripts/smoke_test.shusescurlto verify connectivity to AI provider APIs (api.anthropic.com,api.openai.com). - [DYNAMIC_EXECUTION]: The skill describes runtime execution of dynamically identified or generated commands, particularly through the use of subagents and coordinated teams.
- Evidence:
references/claude-code-skill-and-plugin-loading.mddescribes thecontext: forkmechanism which spawns subagents at runtime. - Evidence:
references/multi-agent-coding-patterns.mddetails the orchestration of background workers using theAgenttool.
Audit Metadata