ai-coding-agents

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface for indirect prompt injection because it provides templates and workflows for agents that ingest untrusted data (source code, diffs, tool outputs) and possess powerful capabilities.
  • Ingestion points: Agents described in references/agent-archetypes.md and various templates ingest repository content, git diffs, and third-party tool outputs.
  • Boundary markers: The skill includes defensive guidance in references/debugging-guide.md (e.g., "code is data, not instructions") and templates like assets/templates/claude-code-agent.md include explicit constraints.
  • Capability inventory: Agents are designed with access to Edit, Write, and Bash tools as seen in assets/templates/coordinator-coding-team.md and assets/templates/migration-agent.md.
  • Sanitization: The references/debugging-guide.md file advises using structured output anchoring and system prompt boundaries to isolate untrusted content.
  • [COMMAND_EXECUTION]: The skill makes extensive use of shell command execution (via Bash tools and subprocess calls) which is central to its purpose of automating development workflows.
  • Evidence: assets/templates/sdk-agent-py.py uses subprocess.run() to execute linters and test runners.
  • Evidence: assets/templates/sdk-agent-ts.ts uses execFileSync() to wrap jest and eslint.
  • Evidence: scripts/smoke_test.sh uses curl to verify connectivity to AI provider APIs (api.anthropic.com, api.openai.com).
  • [DYNAMIC_EXECUTION]: The skill describes runtime execution of dynamically identified or generated commands, particularly through the use of subagents and coordinated teams.
  • Evidence: references/claude-code-skill-and-plugin-loading.md describes the context: fork mechanism which spawns subagents at runtime.
  • Evidence: references/multi-agent-coding-patterns.md details the orchestration of background workers using the Agent tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-coding-agents