fincept-orchestrator
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill discloses a hardcoded absolute local path (
D:\FinceptTerminal\fincept-terminal-desktop\), which provides information about the underlying host environment's file structure. - [PROMPT_INJECTION]: The orchestrator is vulnerable to indirect prompt injection as it ingests untrusted user input and directs it to sub-agents with execution capabilities without explicit security boundaries.
- Ingestion points: User feature requests entering the agent context during the 'Phase 0: Feature Intake' workflow.
- Boundary markers: None implemented to distinguish between user-supplied content and the system's operational instructions.
- Capability inventory: The orchestrator manages agents that execute build tools (
bun run), run backend tests (cargo test), perform data analysis (pytest), and update versioning scripts. - Sanitization: No validation or sanitization mechanisms are described for scrubbing user input before it is consumed by the specialized agents.
- [COMMAND_EXECUTION]: The orchestration protocol includes the execution of various development and build commands, such as
cargo test,pytest,bun run tauri:build, andscripts/bump-version.js.
Audit Metadata