mixture-of-experts
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a Mixture of Experts audit workflow that ingests external content such as codebases, plans, or evidence archives. This creates a surface where malicious instructions embedded in that data could influence the behavior of the subagents or the parent synthesis.
- Ingestion points: The skill processes any topic, plan, codebase, evidence archive, or process provided by the user as audit targets (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or clear separation between the task instructions and the untrusted data being audited.
- Capability inventory: The skill uses a subagent tool to launch independent audit threads and can transition to an "Execution mode" where it applies file changes and runs validation commands.
- Sanitization: No explicit sanitization, filtering, or validation of the ingested audit material is defined in the workflow.
- [COMMAND_EXECUTION]: The workflow describes execution modes involving running generators, validation checks, and harness probes which involve local command execution.
- Evidence: The workflow includes an "Execution mode" where it applies changes and validates them via unspecified command-line tools.
- Evidence: The installation instructions recommend the use of
npxto fetch and install the skill steward framework from the vendor.
Audit Metadata