Coding Cli Management
PassAudited by VirusTotal on May 15, 2026.
Findings (1)
The skill enables automated execution of AI coding CLI tools (Claude, Gemini, Qodercli) with high-risk configurations, specifically using flags like `--dangerously-skip-permissions` and `--yolo` in `scripts/run-coding-cli.sh`. While these are intended to facilitate autonomous coding, they allow AI-generated prompts from 'Worker' agents to execute arbitrary file system changes and commands on the Manager's host without human intervention. The architecture is highly vulnerable to indirect prompt injection, where a malicious or compromised worker could leverage the Manager's elevated privileges to perform unauthorized actions, though no explicit evidence of intentional malice was found.
