skills/boshu2/agentops/orchestrate/Gen Agent Trust Hub

orchestrate

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an orchestrator that ingests and acts upon data from the external environment, creating a potential surface for instructions embedded in data to influence the agent's coordination logic.
  • Ingestion points: In SKILL.md, the instructions describe recovering "accepted outcome, examples and scope" from current owners and inspecting "prerequisite content in the intended checkout."
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading these external outcomes or prerequisites.
  • Capability inventory: The skill coordinates worker dispatching, updates native handoffs, and manages workspace state through external trackers and runtimes.
  • Sanitization: The skill does not mention sanitizing, escaping, or validating the external content retrieved from the checkout or task tracker before using it to guide the next dispatch decision.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 10:55 AM
Security Audit — agent-trust-hub — orchestrate