voltagent-multiagent

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The framework design ingests untrusted data into agent contexts, representing a potential surface for indirect prompt injection where embedded instructions could influence agent behavior.
  • Ingestion points: Input schemas for researcherAgent and summarizeTool, and the task argument in the supervisor's run method in skill.md.
  • Boundary markers: The provided code examples do not demonstrate the use of delimiters or specific boundary instructions to isolate user-provided data from system prompts.
  • Capability inventory: The framework supports web search, text summarization, and the coordination of multiple agents with shared memory.
  • Sanitization: While the framework uses zod for structural schema validation of inputs, it does not demonstrate natural language filtering or escaping of content interpolated into prompts.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install the @voltagent/core library via npm. This is a standard and expected installation step for implementing the framework described.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:04 PM
Security Audit — agent-trust-hub — voltagent-multiagent