agentica-infrastructure
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The Agentica infrastructure API specification defines a high-surface-area environment for multi-agent coordination, which is susceptible to indirect prompt injection where data from one agent influences another.
- Ingestion Points: The framework includes
BlackboardCache(blackboard.py) for message passing between agents,SharedContext(claude_scope.py) for file operation logging and caching, andCoordinationDB(coordination.py) for tracking broadcasts and tasks. These components ingest data from multiple agents that may be processing untrusted external content. - Boundary Markers: The documentation does not specify the use of delimiters or 'ignore embedded instructions' warnings for data retrieved from the shared blackboard or memory services.
- Capability Inventory: The
create_claude_scopefunction inclaude_scope.pyexplicitly includes high-privilege capabilities such asbash,write_file, andedit_filein the agent execution environment, which could be targeted by injected instructions. - Sanitization: The specification lacks explicit details on sanitization, validation, or escaping of the natural language (prose) or formal content passed through the
SharedContextEntryorHandoffStatestructures. - [COMMAND_EXECUTION]: The documentation for
claude_scope.pyindicates the provision of abashtool within the standard execution scope for agents using this infrastructure, representing a significant capability surface for command execution.
Audit Metadata