my-agent
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
opencode/AGENTS.mdconfiguration file instructs the agent to automatically download and install missing dependencies using the commandnpx skills add <skill-name>immediately without manual intervention. - [COMMAND_EXECUTION]: The
SKILL.mdfile provides several copy-pasteable shell commands (mkdir,cp,diff) for the user to execute to restore configuration files to specific local directories (~/.claude/agents/,~/.codex/, and~/.config/opencode/). - [INDIRECT_PROMPT_INJECTION]: The skill's persona definitions (specifically
agents/boss.mdandagents/note.md) ingest untrusted data from the repository, such as git logs, project memory files, and GitHub issue lists. This metadata could potentially be poisoned with instructions that influence the agent's behavior. - Ingestion points:
agents/boss.md(readsgit log,MEMORY.md),agents/note.md(readsgh issue list). - Boundary markers: Absent. The instructions do not define specific delimiters for separating repository metadata from agent instructions.
- Capability inventory:
gh issue create,Read,Write,Edit,Bash(available inagents/note.md,agents/boss.md). - Sanitization: Absent. There are no explicit instructions to sanitize or escape data read from the repository logs or issues.
- [DATA_EXFILTRATION]: The
agents/note.mdpersona is programmed to automatically create, comment on, and close GitHub issues to report task progress. While designed for reporting purposes, this capability involves sending repository status and summary information to an external service (GitHub).
Audit Metadata