ps-swarm
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill coordinates multiple sub-agents and aggregates their terminal results into a single report, which introduces a risk surface for indirect prompt injection. Ingestion points: Results are collected from workers in Phase C (Aggregate) of the workflow defined in SKILL.md. Boundary markers: The instructions include a manual mitigation by directing the agent not to use raw worker dumps and instead format data into a compact result table. Capability inventory: The skill utilizes the platform's delegation mechanism and writes worker output to temporary directories or local branches. Sanitization: No specific technical instructions are provided for sanitizing or escaping the content returned by sub-agents.
- [EXTERNAL_DOWNLOADS]: The skill attribution metadata in NOTICE.md references a public repository on GitHub hosted by Cursor, a well-known AI code editor.
Audit Metadata