skills/iskron-ai/skills/foreman/Gen Agent Trust Hub

foreman

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to orchestrate and monitor multiple 'worker' agents, which involves ingesting their output, status reports, and pull request feedback. This creates a surface for indirect prompt injection if a worker agent's output contains instructions meant to influence the Foreman.
  • Ingestion points: The agent reads status reports from workers, reviewer comments from PRs, and external event triggers (SKILL.md, sections 3, 4, and 5).
  • Boundary markers: The instructions encourage the agent to treat worker statuses as 'claims' rather than absolute truths and to verify progress against physical 'artifacts' (code changes, commits) rather than just words (section 3).
  • Capability inventory: The skill utilizes vendor-specific iskron_* tools, manages a local registry file to track state, and facilitates communication between workers and the owner.
  • Sanitization: The skill explicitly instructs the agent to 'translate' and 'filter' technical details before passing them to the owner to prevent noise and ensure clarity (section 4).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 06:08 PM
Security Audit — agent-trust-hub — foreman