parallel-subagent-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is composed exclusively of markdown files and contains no executable scripts, binaries, or automated installation commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill framework is designed to ingest and process data from untrusted external sources, such as web search results and public code repositories, creating an inherent attack surface for indirect prompt injection.
  • Ingestion points: Subagents are directed to search the web, GitHub, and blogs as specified in 'references/anti-slop-research.md' and 'references/delegation-patterns.md'.
  • Boundary markers: The instructions utilize structured 'prompt packets' to define tasks, but do not mandate the use of explicit delimiters or 'ignore embedded instructions' warnings for external data.
  • Capability inventory: Orchestrated subagents possess capabilities for web research, codebase exploration, and code implementation.
  • Sanitization: The framework incorporates a conceptual sanitization layer through 'Anti-Slop Research' guidelines and the use of a 'skeptic' role to evaluate source quality and evidence strength.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 08:45 AM
Security Audit — agent-trust-hub — parallel-subagent-orchestrator