agent-orchestrator
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow that ingests untrusted data, creating an indirect prompt injection surface.
- Ingestion points: The skill instructs the agent to read external content from Plans.md or user-defined task lists to map out implementation steps.
- Boundary markers: No specific boundary markers or instructions to treat plan content as untrusted were found.
- Capability inventory: The orchestration logic involves the use of powerful capabilities, specifically the Bash tool for shell execution and the Agent tool for creating autonomous sub-agents.
- Sanitization: There is no explicit sanitization logic described for the input data, although the skill includes a cross-review step to verify implementation quality.
Audit Metadata