skills/go7hic/ystack/swarm/Gen Agent Trust Hub

swarm

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow where a lead agent ingests and aggregates results from multiple independent workers, establishing an indirect prompt injection surface. * Ingestion points: Phase D of SKILL.md involves collecting terminal results and evidence for every required slice. * Boundary markers: The lead agent is instructed to use compact summaries and artifact pointers instead of raw dumps, but explicit delimiters are not specified. * Capability inventory: The orchestration involves spawning parallel workers with 'implement' (write-capable) and 'explore' or 'review' (read-only) roles. * Sanitization: Phase D includes mandatory checks where the lead verifies worker scope, evidence resolution, and result support.
  • [NO_CODE]: The skill is composed entirely of markdown documentation and agent instructions without any embedded scripts, binaries, or executable code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:07 PM
Security Audit — agent-trust-hub — swarm