Agent Orchestrator
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to synthesize and act upon data from multiple agents, which constitutes a surface for indirect prompt injection.\n- Ingestion points: Data enters the orchestration context in file SKILL.md via Workflow 1 (Step 6), Workflow 2 (Step 5), and Workflow 3 (Step 2), where outputs from various agents are collected and synthesized.\n- Boundary markers: The skill relies on Markdown-based delegation templates but lacks explicit instructions to the orchestrator to ignore or filter embedded instructions within the aggregated agent outputs before taking subsequent actions.\n- Capability inventory: The orchestration logic can trigger agents that use powerful tools, such as Playwright for web interaction and Supabase/GitHub for data management, as detailed in the Agent Capabilities Map section of SKILL.md.\n- Sanitization: The skill includes a Best Practices section recommending handoff validation and schema checks, which provides a recommended defense, but no automated sanitization or instruction-filtering is implemented in the skill instructions itself.
Audit Metadata