parallel-dispatch

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple local shell scripts and commands to manage the orchestration lifecycle.
  • Evidence: Calls scripts/worktree-manager.sh with various arguments (create, bulkhead-limits, bulkhead-watchdog, cleanup-all) to manage system resources and process isolation.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic context injection syntax to read local protocol files into the agent's context during load.
  • Evidence: !cat skills/_shared/protocols/parallel-protocol.md 2>/dev/null || echo "..." in SKILL.md used for subagent coordination.
  • [DYNAMIC_EXECUTION]: The skill generates implementation instructions and contract files dynamically before spawning new AI agent processes.
  • Evidence: Phase 4.1 involves using cat to write WORKER_INSTRUCTIONS.md containing specific role and boundary rules for sub-processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific configuration and dependency files which could be influenced by external input.
  • Ingestion points: Reads .forgewright/settings.md, .production-grade.yaml, and phase dispatcher files (e.g., phases/build.md).
  • Boundary markers: Uses CONTRACT.json to define explicit input/output boundaries and implemented the 'DeerFlow Pattern' for context isolation (Phase 3.5).
  • Capability inventory: Can execute shell scripts via scripts/worktree-manager.sh and spawn new Gemini CLI instances.
  • Sanitization: Implements context size budgets and guardrail middleware to enforce file-level access control for sub-workers.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — parallel-dispatch