orch-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The orchestration pipeline processes untrusted data from multiple external sources, creating a surface for indirect prompt injection. \n
- Ingestion points: The Intake phase (Step 0) and Research phase (Step 1) ingest data from user-provided specification documents (in the build-mvp operation), GitHub repository/code search results, package registry metadata, and Exa search engine results. \n
- Boundary markers: The skill instructions do not explicitly define boundary markers or provide instructions to the agent to ignore potentially malicious embedded commands within the processed documentation or search results. \n
- Capability inventory: The skill has significant capabilities, including file system writes (via the Implement phase), command execution (via gh search), and git operations (via the Commit phase). \n
- Sanitization: No specific sanitization, filtering, or validation logic is described for the external content before it is processed by the planner or implementation agents. \n
- Mitigation: The risk is effectively mitigated by the mandatory human-in-the-loop gates (Gate 1 and Gate 2) which require user approval for all plans and code commits, and the automatic trigger of a security reviewer for sensitive changes.
Audit Metadata