swarm
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes output from multiple parallel workers which constitutes an indirect prompt injection attack surface.
- Ingestion points: Phase C (Aggregation) involves reading terminal results from N parallel workers (SKILL.md).
- Boundary markers: The instructions do not specify using delimiters or 'ignore instructions' markers when handling worker results.
- Capability inventory: The skill utilizes the agent's ability to spawn subagents and generate consolidated reports in the chat (SKILL.md).
- Sanitization: The instructions do not require sanitizing, escaping, or filtering the data received from workers before it is incorporated into the final report.
Audit Metadata