dynamic-agents
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions direct the agent to read the configuration file
~/.codex/config.tomlto verify the active model version of the Codex CLI. While configuration files in home directories can contain sensitive data, this access is specifically scoped to version verification for a tool provided by a trusted vendor. - [INDIRECT_PROMPT_INJECTION]: As an orchestration skill, it ingests complex user tasks and repository content to generate briefs for sub-agents, which represents an indirect prompt injection surface.
- Ingestion points: Task descriptions provided by the user and source code from the repository being processed (e.g., during repository-wide audits or migrations).
- Boundary markers: The instructions explicitly state that sub-agent prompts must be "self-contained" and that sub-agents do not share the primary conversation context, which serves as a security boundary.
- Capability inventory: The skill possesses the capability to spawn background agents via the
AgentandWorkflowtools, write to the file system (including via git worktrees), and interact with external CLI tools. - Sanitization: The skill does not describe specific input sanitization or filtering logic before delegating tasks to sub-agents.
Audit Metadata