offensive-supervisor-role
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The supervisor role is designed to ingest and analyze evidence artifacts and status reports from sub-agents interacting with external targets.
- Ingestion points: The supervisor processes 'observed' strings and technical artifacts like HTTP responses and tool logs provided by worker roles in SKILL.md and references/decision-and-error-journaling.md.
- Boundary markers: Although the skill prescribes structured context blocks for dispatching tasks, it does not define clear delimiters or 'ignore instructions' wrappers for the data returned from workers to ensure the supervisor ignores embedded instructions.
- Capability inventory: The role is restricted to high-level orchestration and delegation; it is explicitly instructed in SKILL.md not to execute tools like nmap or sqlmap directly, which limits the potential impact of an injection.
- Sanitization: The instructions in references/decision-and-error-journaling.md mandate that worker output be preserved 'verbatim' and that each level 'wraps' the level below, ensuring that potentially malicious content from the target remains intact as it moves up the chain of command.
Audit Metadata