agentic-offensive-orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and provides mitigation strategies for indirect prompt injection surfaces where sub-agents ingest untrusted data from targets.
- Ingestion points: The skill describes agents ingesting data from external sources such as HTTP headers, log lines, SQL rows, and file contents (mentioned in
SKILL.md). - Boundary markers: The skill explicitly recommends the use of XML-style boundary markers (e.g.,
<external_output>) to delimit untrusted content and instructions for the agent to treat such content as data only. - Capability inventory: The orchestration framework described involves use of MCP tools, subprocess execution for security tools (e.g.,
curl,nmap), and file system access. - Sanitization: The skill advocates for strict JSON schema validation for worker outputs and warns against concatenating raw target output directly into prompts without fencing.
- [COMMAND_EXECUTION]: The skill discusses command execution in the context of security tooling (e.g.,
nmap -O,curl) but focuses on restricting these capabilities to scoped, privileged workers to prevent host-level compromise. - [DATA_EXFILTRATION]: The skill provides defensive guidelines to prevent data exfiltration, such as keeping API keys in the orchestrator rather than the workers and routing worker egress through controlled proxies.
Audit Metadata