kf-g-agent-orchestrator
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its architecture of ingesting and acting upon data fetched from external web sources.
- Ingestion points: Worker reports containing data from
WebSearch,WebFetch, andbrowseroperations as defined inSKILL.md. - Boundary markers: The
delegation-instruction.mdtemplate provides structural headers but lacks specific instructions to isolate untrusted content or delimiters to prevent the model from following embedded commands. - Capability inventory: The orchestrator is capable of initiating worker tasks that perform sensitive actions such as
Shell / コマンド実行andファイル編集・削除(SKILL.md). - Sanitization: The skill does not implement sanitization or verification of data retrieved from external sources before it is processed by the orchestrator.
Audit Metadata