ralph-kage-bunshin-debug
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several shell commands to perform its diagnosis and reporting tasks. Evidence includes the use of
grepto search code,agent-browserfor UI inspection, andcurlfor reporting results to a local endpoint. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It reads content from potentially untrusted files like
.ralph/workers/worker-N/PROGRESS.md, error messages, and source code. An attacker could inject instructions into these files to influence the agent's diagnosis or the data it sends externally via local commands. - [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@anthropic-ai/agent-browserpackage if it is not already present. This package is provided by a well-known, trusted organization.
Audit Metadata