kf-g-agent-orchestrator

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its architecture of ingesting and acting upon data fetched from external web sources.
  • Ingestion points: Worker reports containing data from WebSearch, WebFetch, and browser operations as defined in SKILL.md.
  • Boundary markers: The delegation-instruction.md template provides structural headers but lacks specific instructions to isolate untrusted content or delimiters to prevent the model from following embedded commands.
  • Capability inventory: The orchestrator is capable of initiating worker tasks that perform sensitive actions such as Shell / コマンド実行 and ファイル編集・削除 (SKILL.md).
  • Sanitization: The skill does not implement sanitization or verification of data retrieved from external sources before it is processed by the orchestrator.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 12:17 AM
Security Audit — agent-trust-hub — kf-g-agent-orchestrator