orchestrator-herdr

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the execution of shell commands through the herdr CLI toolset to manage worker agents and terminal panes. Key operations include starting agents (herdr agent start), sending prompts (herdr agent send), waiting for status changes (herdr agent wait), and closing panes (herdr pane close). While these are functional requirements for an orchestrator, they represent a significant control surface over the execution environment.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection (Category 8) due to its role as an orchestrator that consumes data from other agents.
  • Ingestion points: Ingests worker transcripts and STATUS.md files as described in SKILL.md (Step 4) and WORKFLOW.md (Step 3).
  • Boundary markers: No explicit delimiters or instructions are used to distinguish ingested worker content from the orchestrator's own system instructions.
  • Capability inventory: The orchestrator has the capability to execute commands, manage other agents, and manipulate the user's terminal environment through the herdr toolset.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of worker-produced data before it is incorporated into the orchestrator's decision-making logic or interpolated into future worker prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:53 AM
Security Audit — agent-trust-hub — orchestrator-herdr