orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The orchestrator is designed to detect capability gaps and trigger the creation of new specialized skills at runtime. It uses the skill-coach tool and file-writing capabilities (Write, Edit) to generate and integrate these new skills. While this is the intended purpose, it represents a mechanism for dynamic capability expansion that could be misused to introduce unexpected behaviors into the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes high-level, complex user instructions to perform task decomposition and orchestration, creating an attack surface where untrusted data could influence the agent. 1. Ingestion points: User requests triggering the 'orchestrate' or 'coordinate' logic in SKILL.md. 2. Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within user-provided task descriptions. 3. Capability inventory: The orchestrator has access to Bash, Write, Edit, Grep, Glob, and Task tools across the file system. 4. Sanitization: No input validation or sanitization of user-provided task descriptions is performed before they are used to generate new skills or determine orchestration steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:34 AM
Security Audit — agent-trust-hub — orchestrator