cross-host-federation

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-host communication mesh where an agent processes messages (claims, status, results) from external peers. This ingestion of data from the network represents a surface for indirect prompt injection. \n
  • Ingestion points: Data enters the context via the federation_bbs_sync tool, which pulls remote message envelopes, and the federation_bbs_watch tool, which monitors room messages. \n
  • Boundary markers: The skill documentation includes an explicit security warning instructing the agent to treat message content as data rather than commands and to validate it before performing side-effectful tasks. \n
  • Capability inventory: The environment includes tools for network serving and synchronization, identity management, and a tool for file reading (Read). \n
  • Sanitization: The architecture implements Ed25519 signature verification to ensure message origin and integrity from pinned peers, but the skill relies on manual validation of the payload content by the agent or user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 11:08 PM
Security Audit — agent-trust-hub — cross-host-federation