agents
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data such as logs, transcripts, and execution traces from other agents to perform diagnostic autopsies.
- Ingestion points: The
references/analyze.mdfile directs the agent to gather 'runtime evidence' from external transcripts, run IDs, and logs (e.g., Langfuse, PostHog, OTel). - Capability inventory: The skill possesses capabilities to modify the local file system (
git checkout,git status) and interact with remote workflow engines (Trigger.dev, CI jobs). - Sanitization: No specific sanitization or filtering protocols are defined for the ingested log data.
- Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions when processing external agent traces.
- [DYNAMIC_EXECUTION]: The skill implements a delegation pattern where it generates dynamic instructions for subagents to execute bounded tasks.
- Mechanism: The
sub/sub-agentsfunctionality involves creating a 'parent brief' that dictates goals and constraints for child agents. - Safeguards: The skill includes defensive rules to prevent overlapping write ownership, mandates explicit 'done-when' criteria, and includes an emergency 'slap' protocol to cancel children that exhibit looping behavior.
Audit Metadata