orchestrate

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and provides a framework for agent-to-agent task delegation. It does not include executable scripts, shell commands, or network operations.
  • [PROMPT_INJECTION]: The skill manages context flow between agents via the chat and structured briefs (ingestion point). It uses defined templates in flow.md with 'Active Rules' and 'Escalation boundaries' (boundary markers) to control worker behavior. Tools like '/validate' and '/code-review' are used within defined file lanes (capability inventory). Instructions require explicit briefs and forbid agents from inferring user intent from opaque paths (sanitization).
  • [DATA_EXFILTRATION]: The skill does not define any processes for accessing sensitive credentials or transmitting data to external endpoints. The workflow emphasizes that no worker reads or updates agent-owned runtime files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 06:04 PM
Security Audit — agent-trust-hub — orchestrate