team

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external CLI tools and packages including @openai/codex, @google/gemini-cli, and the Antigravity CLI from Google (antigravity.google). These resources originate from well-known and trusted technology organizations.
  • [INDIRECT_PROMPT_INJECTION]: The orchestrator agent functions by ingesting data from the project codebase and output generated by subagents or CLI workers. This creates a surface for indirect prompt injection if the processed files contain malicious instructions. However, the skill incorporates mitigation strategies including worker preambles to enforce protocols and name sanitization for branch creation.
  • [COMMAND_EXECUTION]: The skill uses shell commands for environment setup, process management (e.g., tmux, git worktrees), and executing local scripts like cleanup-orphans.mjs. These operations are consistent with the skill's primary purpose as a developer-oriented orchestration tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 08:41 PM
Security Audit — agent-trust-hub — team