skills/cursor/plugins/arena/Gen Agent Trust Hub

arena

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill documentation explicitly references and instructs the use of the !command syntax (e.g., !arena runners). In specific agent environments, this syntax executes shell commands at skill load time to populate context.
  • [INDIRECT_PROMPT_INJECTION]: The 'Phase C: Cross-judge' and 'Phase D: Pick a base' stages involve the agent processing and judging artifacts generated by multiple external runners. This represents an attack surface where instructions embedded in candidate outputs could attempt to influence the parent agent's decision-making or synthesis logic.
  • [COMMAND_EXECUTION]: The workflow describes execution of shell commands for environment setup, such as creating git worktrees or temporary directories (/tmp/arena-<slug>/).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:37 PM
Security Audit — agent-trust-hub — arena