team
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several external CLI tools and packages including
@openai/codex,@google/gemini-cli, and the Antigravity CLI from Google (antigravity.google). These resources originate from well-known and trusted technology organizations. - [INDIRECT_PROMPT_INJECTION]: The orchestrator agent functions by ingesting data from the project codebase and output generated by subagents or CLI workers. This creates a surface for indirect prompt injection if the processed files contain malicious instructions. However, the skill incorporates mitigation strategies including worker preambles to enforce protocols and name sanitization for branch creation.
- [COMMAND_EXECUTION]: The skill uses shell commands for environment setup, process management (e.g., tmux, git worktrees), and executing local scripts like
cleanup-orphans.mjs. These operations are consistent with the skill's primary purpose as a developer-oriented orchestration tool.
Audit Metadata