orchestrator-mode
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it directs the agent to ingest and act upon data from handoff documents and sub-agent reports. Ingestion points: handoff docs, referenced URLs, and agent reports. Boundary markers: Absent. Capability inventory: delegation tools, ctx_execute, and git operations. Sanitization: Absent.
- [SAFE]: No malicious patterns such as obfuscation, credential theft, or unauthorized persistence mechanisms were detected. The use of local temporary storage for handoff documents is a standard collaborative workflow.
- [SAFE]: The skill does not perform any remote code downloads or install external dependencies from untrusted sources.
Audit Metadata