code-architect

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill ingests untrusted task context into a subagent call. Ingestion points: bash heredoc in SKILL.md. Boundary markers: EOF heredoc (stops shell expansion but not subagent instruction override). Capability inventory: execution of codex-subagent. Sanitization: none.
  • [Command Execution] (LOW): The skill executes the codex-subagent utility. This behavior is the primary purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:39 PM