team-agent-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No code or executable scripts are included in this skill. It consists entirely of markdown instructions for agent orchestration and management.
  • [SAFE]: References to third-party tools (e.g., tmux, Zellij, Devin) and other agent platforms are strictly for operational context and do not include installation commands or remote downloads.
  • [INDIRECT_PROMPT_INJECTION]: The orchestration model involves ingesting data from multiple agents, which represents a potential attack surface for indirect instructions.
  • Ingestion points: Data enters the context via handoff artifacts, logs, and work items described in SKILL.md.
  • Boundary markers: No specific delimiters or explicit instructions to ignore embedded commands are provided for processed artifacts.
  • Capability inventory: The workflow implies file system writes and branch management capabilities for the orchestrating agent.
  • Sanitization: The skill relies on manual human/agent 'Review' and 'Merge gate' processes for verification rather than automated sanitization of ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — team-agent-orchestration