klh-dispatch
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses user-supplied intent and task descriptions to determine its planning and execution flow, making it susceptible to malicious instructions embedded in the task data.
- Ingestion points: User intent strings and task descriptions processed by the routing table and orchestration loop in SKILL.md.
- Boundary markers: Absent; there are no explicit delimiters or instructions to ignore embedded commands within the user-provided tasks.
- Capability inventory: Spawns parallel sub-agents and invokes multiple specialized skills (e.g., klh-find-bugs, klh-systematic-debugging, klh-cli-speed-tools) that perform file and CLI operations.
- Sanitization: The workflow includes a planning checkpoint for user approval (Phase 1) and a verification phase (Phase 3) that utilizes a bug-finding skill and checks for failure modes like tool misuse and context loss.
Audit Metadata