chief-of-staff

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions specify that the agent should coordinate subagents using "context pointers" such as research notes and previous commits. This creates an ingestion surface where untrusted data from these external sources could contain instructions that influence the agent's behavior.
  • Ingestion points: The skill processes external artifacts described as "research notes" and "previous commits" in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore instructions embedded within the context pointers.
  • Capability inventory: The skill coordinates subagents for tactical work. While disable-model-invocation: true is set for this specific skill configuration, the coordination logic implies a pipeline where influenced decisions could lead to downstream actions by other agents.
  • Sanitization: No sanitization or validation of the content within the context pointers is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:20 AM
Security Audit — agent-trust-hub — chief-of-staff