letta-fleet-management

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive reference guide for agent fleet orchestration. All described functionalities, including agent creation, memory management, and deployment workflows, align with standard administrative operations.
  • [COMMAND_EXECUTION]: The documentation outlines the use of the lettactl CLI and the execution of Model Context Protocol (MCP) servers (e.g., using npx to run @anthropic/mcp-server-filesystem). These are documented features for agent extensibility.
  • [EXTERNAL_DOWNLOADS]: The skill references the vendor's own package (lettactl) and tools from well-known organizations (Anthropic) and services (Supabase, Firecrawl). These references are informative and originate from trusted sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines ingestion points for external data via memory blocks and boot messages (first_message). While these represent a surface for data ingestion, the documentation focuses on declarative configuration rather than unsafe processing of untrusted input. Capabilities include file writing and tool execution as specified in the fleet configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — letta-fleet-management