chief-of-staff
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a management role for coordinating multiple agents, focusing on filtering outputs and monitoring agent status. All tool invocations (iskron_realm, iskron_me, iskron_search, iskron_channel, iskron_admin) are part of the iskron-ai vendor ecosystem and are used for their intended orchestration purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a communication hub between agents and the human user, which naturally creates an attack surface for indirect prompt injection from agent outputs. However, the skill provides extensive instructions for filtering, provenance tracking, and human-in-the-loop escalation for irreversible or sensitive actions, which are standard security practices for this role.
- [SAFE]: The skill does not contain any hardcoded credentials, unauthorized network operations, or obfuscated code. It manages webhooks and sockets exclusively through vendor-provided administrative tools.
Audit Metadata