claude-devfleet

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied strings that are then passed to downstream autonomous agents. • Ingestion points: The prompt parameters in plan_project and create_mission tools serve as the entry points for untrusted data. • Boundary markers: The skill instructions do not specify any delimiters (e.g., XML tags or triple quotes) or 'ignore embedded instructions' warnings when passing data to the sub-agents. • Capability inventory: According to the skill description, dispatched agents have 'full tooling' and operate within git worktrees, which involves file system writes and command execution. • Sanitization: There is no evidence of escaping or validation of these prompts before they are passed to the dispatch_mission tool.
  • [COMMAND_EXECUTION]: The orchestration platform manages agents designed to perform shell-based tasks and repository modifications. While this is the core functionality, the skill relies on a local MCP server (http://localhost:18801) to perform these operations, granting the orchestrated agents significant local execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — claude-devfleet