autogen-multi-agent-workflow

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a security-first approach to agent orchestration. It explicitly prohibits common vulnerabilities such as relying on prompt instructions for loop termination, instead requiring code-enforced gates.
  • [COMMAND_EXECUTION]: The skill enforces a 'closed set' tool surface. It requires that tools be registered only on authorized agents (least privilege) and that authorization is verified at execution time, ensuring the model cannot propose unapproved tool calls.
  • [CREDENTIALS_UNSAFE]: The skill mandates that all credentials and sensitive configurations are injected at deployment time. It includes specific quality checks to ensure no secrets, PII, or raw tool payloads are leaked in traces or logs.
  • [PROMPT_INJECTION]: The skill includes guidelines for maintaining a prompt-injection posture across agent messages and requires explicit boundary markers and budget enforcement (max turns, wall-clock time) to prevent resource exhaustion or loop-based attacks.
  • [DATA_EXFILTRATION]: The skill defines strict memory and session storage policies, including required redaction and scoping, to prevent unauthorized data exposure between agents or sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — autogen-multi-agent-workflow