backend-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a structured workflow for coordinating backend development (APIs, databases, services) through checklists and data definitions. It does not include executable shell commands, binary files, or network operation code.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted data from external sources.
  • Ingestion points: 'Task Processing Flow' (Receive Task) and 'Event Communication' (Listening For events like frontend.api.request).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the ingested data.
  • Capability inventory: The skill delegates tasks to other specialized skills and monitors execution, involving the potential use of validation tools and file system updates (e.g., updating backend-developer.md).
  • Sanitization: While the checklists include requirements for SQL injection prevention in the generated code, there is no explicit sanitization for the inputs being processed by the agent.
  • [SAFE]: The metadata file 'skill-report.json' includes fictional or placeholder references (e.g., model version 'gpt-5.5') and erroneous static analysis findings (misidentifying markdown backticks as shell execution), but these do not impact the security of the skill implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:14 AM
Security Audit — agent-trust-hub — backend-orchestrator