Coding Agent Local
PassAudited by VirusTotal on Mar 24, 2026.
Findings (1)
The skill bundle provides instructions for delegating tasks to external coding agents (Codex, Claude Code, Pi) using high-risk flags such as '--yolo' and '--permission-mode bypassPermissions' which explicitly disable safety prompts and sandboxing. While these are presented as features for automation, they create a significant risk for unintended or autonomous system modifications. The instructions in SKILL.md also detail background execution patterns and the use of PTY for interactive CLIs, which are powerful capabilities that lack sufficient guardrails if the sub-agent is misdirected.
