agent-team-orchestration

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a protocol for agents to ingest and process tasks and specifications, which creates an inherent attack surface for indirect prompt injection. The skill mitigates this by establishing strict role boundaries and mandatory review cycles.
  • Ingestion points: Task records and specification files (e.g., /shared/specs/) described in SKILL.md and references/task-lifecycle.md.
  • Boundary markers: Defined handoff protocols, structured task comment conventions, and role-specific SOUL.md identity files provide clear operational constraints.
  • Capability inventory: Builder agents are authorized to generate code and configurations, which are subsequently verified by independent Reviewer agents as per the references/patterns.md workflow.
  • Sanitization: The protocol emphasizes human or peer review of all artifacts to catch potential issues like SQL injection or information exposure before completion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 09:47 PM
Security Audit — agent-trust-hub — agent-team-orchestration