multi-agent-workforce-planner
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an orchestration layer that ingests and processes untrusted data (Product Requirement Documents and codebase files) which may contain malicious instructions designed to influence the agent's planning or execution stages.
- Ingestion points: The skill is designed to analyze external Product Requirement Documents (PRDs) and existing source code files to generate dependency graphs and task lists, as seen in
SKILL.mdandreferences/dependency-analysis.md. - Boundary markers: The planning framework uses structured YAML and Markdown, but does not provide specific instructions or delimiters to isolate or ignore potentially adversarial instructions embedded in the input feature specifications.
- Capability inventory: The orchestrator manages agents with significant permissions, including the
Editagent for file writes and theBashagent for shell execution, git operations, and network webhooks, as detailed inreferences/agent-type-catalog.mdandreferences/workflow-integration.md. - Sanitization: The skill lacks explicit sanitization or validation logic for the instructions extracted from external data before they are used to drive the actions of implementation and automation agents.
Audit Metadata