agentic-offensive-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and provides mitigation strategies for indirect prompt injection surfaces where sub-agents ingest untrusted data from targets.
  • Ingestion points: The skill describes agents ingesting data from external sources such as HTTP headers, log lines, SQL rows, and file contents (mentioned in SKILL.md).
  • Boundary markers: The skill explicitly recommends the use of XML-style boundary markers (e.g., <external_output>) to delimit untrusted content and instructions for the agent to treat such content as data only.
  • Capability inventory: The orchestration framework described involves use of MCP tools, subprocess execution for security tools (e.g., curl, nmap), and file system access.
  • Sanitization: The skill advocates for strict JSON schema validation for worker outputs and warns against concatenating raw target output directly into prompts without fencing.
  • [COMMAND_EXECUTION]: The skill discusses command execution in the context of security tooling (e.g., nmap -O, curl) but focuses on restricting these capabilities to scoped, privileged workers to prevent host-level compromise.
  • [DATA_EXFILTRATION]: The skill provides defensive guidelines to prevent data exfiltration, such as keeping API keys in the orchestrator rather than the workers and routing worker egress through controlled proxies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — agentic-offensive-orchestration