long-task-control

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its requirement to ingest and process external task data. \n- Ingestion points: The skill instructs the agent to read "actual artifacts, checks, remaining work, history or rollout, and active agents" in SKILL.md. \n- Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested content or to warn the agent against following instructions embedded within those artifacts. \n- Capability inventory: The agent is granted the authority to "interrupt an active delegate", "re-decompose the remaining work", and "retire stale agents" based on its evaluation of the ingested content. \n- Sanitization: The skill lacks any requirement for escaping, filtering, or validating external content before it influences decision-making.\n- [NO_CODE]: The skill does not include any executable scripts, binaries, or external code dependencies, which limits its operational surface to the interpretation of natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 05:27 PM
Security Audit — agent-trust-hub — long-task-control