claude-devfleet
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes and interpolates user-provided prompts into the operational context of secondary agents.\n- Ingestion points: The
promptparameters inplan_projectandcreate_missiontools serve as entry points for untrusted data.\n- Boundary markers: No delimiters or safety instructions are specified to help sub-agents distinguish between system instructions and potentially malicious payload content.\n- Capability inventory: Orchestrated agents are granted 'full tooling' and operate within git worktrees, enabling file and system interactions.\n- Sanitization: The documentation does not describe any validation or filtering mechanisms for mission prompts before they are dispatched to agents.
Audit Metadata