claude-devfleet
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied strings that are then passed to downstream autonomous agents. • Ingestion points: The
promptparameters inplan_projectandcreate_missiontools serve as the entry points for untrusted data. • Boundary markers: The skill instructions do not specify any delimiters (e.g., XML tags or triple quotes) or 'ignore embedded instructions' warnings when passing data to the sub-agents. • Capability inventory: According to the skill description, dispatched agents have 'full tooling' and operate within git worktrees, which involves file system writes and command execution. • Sanitization: There is no evidence of escaping or validation of these prompts before they are passed to thedispatch_missiontool. - [COMMAND_EXECUTION]: The orchestration platform manages agents designed to perform shell-based tasks and repository modifications. While this is the core functionality, the skill relies on a local MCP server (
http://localhost:18801) to perform these operations, granting the orchestrated agents significant local execution capabilities.
Audit Metadata