parallel-agents
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation describes an architectural pattern for parallel agent orchestration that relies on a central agent reading status and output files generated by sub-agents. This pattern introduces a surface for indirect prompt injection if a sub-agent is compromised or processes untrusted input that is then written to the shared files.
- Ingestion points: The orchestration logic in SKILL.md involves reading files such as .claude/cache/-status.txt and output.md.
- Boundary markers: No specific delimiters or boundary markers are suggested for the data read from sub-agent files.
- Capability inventory: The agent context includes shell command execution (cat, wc, tail) and the ability to spawn new sub-agents.
- Sanitization: The instructions do not include guidance on sanitizing or validating the content written by sub-agents before it is ingested by the main agent.
Audit Metadata