backend-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a structured workflow for coordinating backend development (APIs, databases, services) through checklists and data definitions. It does not include executable shell commands, binary files, or network operation code.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process untrusted data from external sources.
- Ingestion points: 'Task Processing Flow' (Receive Task) and 'Event Communication' (Listening For events like frontend.api.request).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the ingested data.
- Capability inventory: The skill delegates tasks to other specialized skills and monitors execution, involving the potential use of validation tools and file system updates (e.g., updating backend-developer.md).
- Sanitization: While the checklists include requirements for SQL injection prevention in the generated code, there is no explicit sanitization for the inputs being processed by the agent.
- [SAFE]: The metadata file 'skill-report.json' includes fictional or placeholder references (e.g., model version 'gpt-5.5') and erroneous static analysis findings (misidentifying markdown backticks as shell execution), but these do not impact the security of the skill implementation.
Audit Metadata