sub-agent-dispatch

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation provides instructions for installing vendor-maintained tools such as agents-mcp and compose-agentsmd. These tools are fetched from the vendor's official GitHub repository or standard package registries and are essential for the skill's functionality.
  • [REMOTE_CODE_EXECUTION]: The skill describes a setup process involving npx to run the agents-mcp server directly from a vendor-owned GitHub repository. This is an intended architectural feature for providing sub-agent orchestration capabilities and originates from the skill's own author.
  • [PROMPT_INJECTION]: As an orchestration skill, it facilitates the flow of data between multiple agents, which naturally creates a surface for indirect prompt injection. The skill includes specific mitigation measures, such as mandatory verification templates and structured review protocols, to ensure sub-agent outputs are validated against original requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 08:59 AM