batch-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The provided skill is a documentation-based guide that describes an architectural pattern for batch orchestration. It does not contain any executable scripts, hardcoded credentials, or network exfiltration logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that ingests and processes repository data (via grep and code scanning), which inherently presents an indirect prompt injection surface where malicious content in the codebase could attempt to influence the agent's behavior.
  • Ingestion points: Repository file content scanned during the Research phase (SKILL.md).
  • Boundary markers: The skill mandates a 'Plan Approval' phase where the user must explicitly confirm the decomposed units before execution.
  • Capability inventory: Shell command execution (grep, git worktree), background agent spawning, and file modification operations.
  • Sanitization: None described in the text; reliance is placed on human review and agent guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — batch-orchestration