mixture-of-experts

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a Mixture of Experts audit workflow that ingests external content such as codebases, plans, or evidence archives. This creates a surface where malicious instructions embedded in that data could influence the behavior of the subagents or the parent synthesis.
  • Ingestion points: The skill processes any topic, plan, codebase, evidence archive, or process provided by the user as audit targets (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or clear separation between the task instructions and the untrusted data being audited.
  • Capability inventory: The skill uses a subagent tool to launch independent audit threads and can transition to an "Execution mode" where it applies file changes and runs validation commands.
  • Sanitization: No explicit sanitization, filtering, or validation of the ingested audit material is defined in the workflow.
  • [COMMAND_EXECUTION]: The workflow describes execution modes involving running generators, validation checks, and harness probes which involve local command execution.
  • Evidence: The workflow includes an "Execution mode" where it applies changes and validates them via unspecified command-line tools.
  • Evidence: The installation instructions recommend the use of npx to fetch and install the skill steward framework from the vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:38 AM
Security Audit — agent-trust-hub — mixture-of-experts