agent-worker-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern where it retrieves dependency information and task assignments from a shared memory tool (mcp__claude-flow__memory_usage). This creates an attack surface where maliciously crafted data in the shared memory could influence the agent's behavior.
- Ingestion points: SKILL.md (retrieval of swarm$shared$dependencies and potentially queen$coordinator tasks).
- Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands in the retrieved memory values.
- Capability inventory: The skill description indicates the agent is expected to perform file modifications (files_modified), create files (files_created), and manage persistent state (store action).
- Sanitization: There is no evidence of validation or sanitization of the values retrieved from memory before they are processed or used to gate task execution.
Audit Metadata