coliseum-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary user-provided input (the 'grain') and uses it to generate and dispatch assignments to other agents. The instructions explicitly direct the agent to avoid clarifying questions and proceed autonomously ('No prompt ping-pong'), which reduces user oversight of the generated sub-tasks. The skill also includes a mechanism to bypass validation gates after three attempts, potentially forcing the execution of risky content.
- Ingestion points: The input 'grain' provided by the user in Phase 0.
- Boundary markers: The grain is stored in 'grain-context.md', but no specific instructions are provided to the agent to sanitize or ignore potentially malicious embedded directives in the content.
- Capability inventory: The skill uses 'Bash', 'Write', 'Edit', and 'Agent' (task dispatch) tools across multiple execution phases.
- Sanitization: There is no evidence of sanitization or safety filtering for the user-supplied content before it is processed or used to generate sub-agent prompts.
- [COMMAND_EXECUTION]: The skill requests and uses the 'Bash' tool to manage the local workspace, including creating directories and files ('grain-context.md', 'phase-1-dimensions.md', etc.) based on slugs derived from user-supplied input strings.
Audit Metadata