Swarm Orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill coordinates agent swarms by ingesting and processing untrusted data, which creates a vulnerability to indirect prompt injection attacks.
- Ingestion points: Task descriptions and goal parameters are ingested via the
--taskargument innpxcommands and thegoalproperty inautoOrchestratemethods withinSKILL.md. - Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' markers to isolate untrusted external content from system-level coordination logic.
- Capability inventory: The skill leverages
agentic-flowhooks for shell-based orchestration, multi-agent spawning, and shared memory access for state coordination. - Sanitization: No evidence of input validation, escaping, or sanitization is present in the provided documentation or orchestration examples.
- [COMMAND_EXECUTION]: The skill facilitates the management of agent swarms through the execution of command-line tools.
- Evidence: Multiple examples in
SKILL.mdusenpx agentic-flowto initialize topologies, spawn agents, and orchestrate complex tasks.
Audit Metadata