agent-delegation-contract

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a protocol where subagents ingest and execute instructions from a markdown-based contract, creating a potential surface for indirect prompt injection if the source data is not trusted.
  • Ingestion points: The DELEGATION CONTRACT template in SKILL.md defines fields like Scope, Input Interface, and Constraints that are populated at runtime and processed by subagents.
  • Boundary markers: The template includes a mandatory Out of Scope section which acts as a logical boundary to restrict subagent actions.
  • Capability inventory: The contract guidelines recommend executing verification commands using npx (e.g., tsc, eslint, vitest).
  • Sanitization: No explicit sanitization or escaping mechanisms are defined for the content interpolated into the contract fields.
  • [COMMAND_EXECUTION]: The skill's verification protocol suggests the execution of common development CLI tools.
  • Evidence: Mentions the use of npx tsc --noEmit, npx eslint src/, and npx vitest run within the Verification Criteria section to ensure code quality and correctness.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — agent-delegation-contract