do-in-parallel
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates as a supervisor that takes user-provided task descriptions and implementer agent outputs and interpolates them into instructions for subsequent agents (Meta-Judges, Implementers, and Judges). Ingestion points: The skill ingests the user-provided
taskargument and the output summaries from implementation agents. Boundary markers: Structural delimiters such as<task>,<target>, and<constraints>tags are used in the generated sub-agent prompts to scope the interpolated data. Capability inventory: The orchestrator utilizes theTasktool to dispatch sub-agents; it is explicitly forbidden from performing direct file system or shell operations itself, ensuring clear role isolation. Sanitization: While the orchestrator does not perform explicit character escaping or input validation, the use of structural tags and the isolation of implementation work to dedicated sub-agents provides significant architectural mitigation.
Audit Metadata