chief-of-staff
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to process external data which serves as a potential vector for indirect prompt injection.
- Ingestion points: The agent is instructed to communicate via "context pointers" including "research notes" and "previous commits" (SKILL.md).
- Boundary markers: The instructions lack delimiters or warnings to ignore instructions that might be embedded within these external data sources.
- Capability inventory: While the skill configuration (SKILL.md) does not list specific dangerous tools, it establishes an orchestrator role that manages subagents.
- Sanitization: There is no mention of sanitizing or validating the content found in the external research notes or commit history before use.
Audit Metadata