multi-agent-workforce-planner

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an orchestration layer that ingests and processes untrusted data (Product Requirement Documents and codebase files) which may contain malicious instructions designed to influence the agent's planning or execution stages.
  • Ingestion points: The skill is designed to analyze external Product Requirement Documents (PRDs) and existing source code files to generate dependency graphs and task lists, as seen in SKILL.md and references/dependency-analysis.md.
  • Boundary markers: The planning framework uses structured YAML and Markdown, but does not provide specific instructions or delimiters to isolate or ignore potentially adversarial instructions embedded in the input feature specifications.
  • Capability inventory: The orchestrator manages agents with significant permissions, including the Edit agent for file writes and the Bash agent for shell execution, git operations, and network webhooks, as detailed in references/agent-type-catalog.md and references/workflow-integration.md.
  • Sanitization: The skill lacks explicit sanitization or validation logic for the instructions extracted from external data before they are used to drive the actions of implementation and automation agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — multi-agent-workforce-planner