worker
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and execute instructions retrieved from external task and mailbox files, creating a surface for potential instruction injection if these files are compromised or contain untrusted content.
- Ingestion points: The agent reads task assignments from
inbox.mdand detailed task data fromtask-<id>.jsonfiles located in the<team_state_root>. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the content of these files as data rather than instructions.
- Capability inventory: The skill possesses the ability to execute shell commands via the
omxCLI tool and perform filesystem writes to state and status files. - Sanitization: The instructions do not specify any validation or sanitization logic for the content parsed from the inbox or task JSON files.
Audit Metadata