claude-devfleet

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external mission reports to influence the agent's next steps and user reporting.
  • Ingestion points: Data enters the context via get_report(mission_id) and user-provided prompts in plan_project and create_mission.
  • Boundary markers: The skill does not define specific delimiters or instructions to the agent to treat mission reports as untrusted data or to ignore embedded instructions within them.
  • Capability inventory: The skill facilitates powerful capabilities including spawning parallel agents (dispatch_mission) with access to the local filesystem and git repositories via isolated worktrees.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of mission report content before it is processed by the orchestrating agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — claude-devfleet