teams-research
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
jqto modify the.claude/settings.local.jsonfile to enable theCLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMSfeature flag. This modification is documented and the user is explicitly prompted to restart the application. - [PROMPT_INJECTION]: The skill ingests data from
spec.mdto identify research topics for sub-agents. This presents an indirect prompt injection surface (Category 8); however, the risk is mitigated as the sub-agents are restricted to read-only operations using tools likeRead,Grep, andGlob, and are explicitly forbidden from modifying files.
Audit Metadata