opc-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a session recovery protocol that automatically reads files from the 'opc-doc/' directory at the start of every session. This directory contains data that may be influenced by previous user inputs or outputs from other skills in the workflow. If malicious instructions were embedded in these state or output files, they could be processed as instructions during the recovery phase.
  • Ingestion points: 'opc-doc/state/current-stage.json', 'opc-doc/state/decisions.json', 'opc-doc/state/assumptions.json', and files within the 'opc-doc/outputs/' subdirectories.
  • Boundary markers: The instructions do not define clear delimiters or 'ignore instructions' directives when summarizing or processing data from these files.
  • Capability inventory: The skill has the ability to write files to the local file system to save state and session summaries.
  • Sanitization: There is no evidence of sanitization or validation logic applied to the content read from the 'opc-doc/' directory before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:22 AM