Swarm Orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill coordinates agent swarms by ingesting and processing untrusted data, which creates a vulnerability to indirect prompt injection attacks.
  • Ingestion points: Task descriptions and goal parameters are ingested via the --task argument in npx commands and the goal property in autoOrchestrate methods within SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' markers to isolate untrusted external content from system-level coordination logic.
  • Capability inventory: The skill leverages agentic-flow hooks for shell-based orchestration, multi-agent spawning, and shared memory access for state coordination.
  • Sanitization: No evidence of input validation, escaping, or sanitization is present in the provided documentation or orchestration examples.
  • [COMMAND_EXECUTION]: The skill facilitates the management of agent swarms through the execution of command-line tools.
  • Evidence: Multiple examples in SKILL.md use npx agentic-flow to initialize topologies, spawn agents, and orchestrate complex tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — Swarm Orchestration