swarm-planner

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it is designed to ingest and process untrusted data from external documentation and local codebase files to generate its output.
  • Ingestion points: The agent is instructed to read existing codebase files and fetch external documentation via web search or tools like Context7.
  • Boundary markers: The instructions lack specific boundary markers or 'ignore' instructions for the content retrieved from these external sources.
  • Capability inventory: The skill allows the agent to write implementation plans to the filesystem and spawn subagents for review, which are capabilities that could be influenced by injected instructions.
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter the data retrieved from external sources before using it in the planning process.
  • [EXTERNAL_DOWNLOADS]: The skill requires the agent to fetch external content for documentation purposes.
  • Source: Retrieves documentation from external libraries, frameworks, and APIs.
  • Method: Uses the 'Context7' skill, MCP tools, or web search to access remote information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 10:36 AM
Security Audit — agent-trust-hub — swarm-planner