agent-worker-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern where it retrieves dependency information and task assignments from a shared memory tool (mcp__claude-flow__memory_usage). This creates an attack surface where maliciously crafted data in the shared memory could influence the agent's behavior.
  • Ingestion points: SKILL.md (retrieval of swarm$shared$dependencies and potentially queen$coordinator tasks).
  • Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands in the retrieved memory values.
  • Capability inventory: The skill description indicates the agent is expected to perform file modifications (files_modified), create files (files_created), and manage persistent state (store action).
  • Sanitization: There is no evidence of validation or sanitization of the values retrieved from memory before they are processed or used to gate task execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-worker-specialist