plan-hiring
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Orchestrates a multi-agent team by programmatically spawning agents with specific personas and tasks using the
Agenttool. - [PROMPT_INJECTION]: Vulnerable to indirect prompt injection as it ingests contents from external files (
docs/,package.json, etc.) into the agent's context. - Ingestion points: Dynamically reads project roadmap, specifications, architecture, and user-provided hiring data from the working directory.
- Boundary markers: Does not utilize specific delimiters or instructions to isolate ingested content from system instructions.
- Capability inventory: Agents have access to
SendMessage,TeamCreate, and file writing tools. - Sanitization: No explicit sanitization or validation of the text read from the project directory is mentioned.
Audit Metadata