voltagent-multiagent
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The framework design ingests untrusted data into agent contexts, representing a potential surface for indirect prompt injection where embedded instructions could influence agent behavior.
- Ingestion points: Input schemas for
researcherAgentandsummarizeTool, and thetaskargument in the supervisor'srunmethod inskill.md. - Boundary markers: The provided code examples do not demonstrate the use of delimiters or specific boundary instructions to isolate user-provided data from system prompts.
- Capability inventory: The framework supports web search, text summarization, and the coordination of multiple agents with shared memory.
- Sanitization: While the framework uses
zodfor structural schema validation of inputs, it does not demonstrate natural language filtering or escaping of content interpolated into prompts. - [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install the
@voltagent/corelibrary vianpm. This is a standard and expected installation step for implementing the framework described.
Audit Metadata