agile-router

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted user input via the $ARGUMENTS variable to determine which agile skill to recommend, creating a surface for indirect prompt injection.
  • Ingestion points: The $ARGUMENTS placeholder is used in SKILL.md to receive context from the user.
  • Boundary markers: Absent; there are no delimiters or specific instructions to help the model distinguish between user data and routing instructions.
  • Capability inventory: The skill is restricted to making text-based recommendations for internal slash commands and does not have access to subprocesses, file-writing, or network operations.
  • Sanitization: No sanitization or validation of the input is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 01:20 PM
Security Audit — agent-trust-hub — agile-router