swarm-coordination

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The coordination workflow facilitates spawning sub-agents using prompts generated by tools at runtime, which may ingest untrusted project data.\n
  • Ingestion points: Tool output from swarm_spawn_subtask and the shared_context variable in SKILL.md.\n
  • Boundary markers: The protocol lacks explicit instructions or delimiters for spawned workers to distinguish between system guidance and potentially untrusted content in the generated prompts.\n
  • Capability inventory: The skill is documented as having access to tools: ["*"] and utilizes the Task tool to delegate work, creating a large capability surface for orchestrated sub-agents.\n
  • Sanitization: No sanitization or safety validation of the generated task prompt is described before execution.\n- [DYNAMIC_EXECUTION]: The worker spawning protocol involves runtime parsing of JSON data to extract executable instructions for sub-agents.\n
  • Evidence: SKILL.md demonstrates a pattern of using JSON.parse() on tool results to extract a prompt which is then passed directly to the Task tool for execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 01:09 AM
Security Audit — agent-trust-hub — swarm-coordination