triumvirate

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for Indirect Prompt Injection due to unsafe interpolation of plan content.
  • Ingestion points: The skill parses plans from the current conversation context or codebase files in SKILL.md Step 1.
  • Boundary markers: Absent. The {plan_text} variable is interpolated directly into subagent prompts in prompts/advocate.md, prompts/analyst.md, and prompts/critic.md without delimiters or 'ignore' instructions.
  • Capability inventory: Subagents are granted powerful tools including codebase access (Glob, Grep, Read) and network access (WebSearch, WebFetch).
  • Sanitization: Absent. No escaping or validation is performed on the ingested content before it is processed by the subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:36 AM
Security Audit — agent-trust-hub — triumvirate