team-agent-orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No code or executable scripts are included in this skill. It consists entirely of markdown instructions for agent orchestration and management.
- [SAFE]: References to third-party tools (e.g., tmux, Zellij, Devin) and other agent platforms are strictly for operational context and do not include installation commands or remote downloads.
- [INDIRECT_PROMPT_INJECTION]: The orchestration model involves ingesting data from multiple agents, which represents a potential attack surface for indirect instructions.
- Ingestion points: Data enters the context via handoff artifacts, logs, and work items described in SKILL.md.
- Boundary markers: No specific delimiters or explicit instructions to ignore embedded commands are provided for processed artifacts.
- Capability inventory: The workflow implies file system writes and branch management capabilities for the orchestrating agent.
- Sanitization: The skill relies on manual human/agent 'Review' and 'Merge gate' processes for verification rather than automated sanitization of ingested content.
Audit Metadata