triumvirate
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for Indirect Prompt Injection due to unsafe interpolation of plan content.
- Ingestion points: The skill parses plans from the current conversation context or codebase files in
SKILL.mdStep 1. - Boundary markers: Absent. The
{plan_text}variable is interpolated directly into subagent prompts inprompts/advocate.md,prompts/analyst.md, andprompts/critic.mdwithout delimiters or 'ignore' instructions. - Capability inventory: Subagents are granted powerful tools including codebase access (
Glob,Grep,Read) and network access (WebSearch,WebFetch). - Sanitization: Absent. No escaping or validation is performed on the ingested content before it is processed by the subagents.
Audit Metadata