boss-advanced

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exclusively contains organizational and procedural instructions for AI agent coordination and does not execute any malicious code or exfiltrate data.
  • [PROMPT_INJECTION]: The skill incorporates defensive prompt engineering via a '6-Section Delegation Prompt Template'. This template uses explicit boundary markers (e.g., MUST DO, MUST NOT DO, EXPECTED OUTCOME) to constrain sub-agent behavior and prevent instruction drift or indirect injection from sub-agent outputs.
  • [COMMAND_EXECUTION]: The skill defines logic for spawning sub-agents and invoking internal skills (e.g., 'team', 'gstack-sprint'). These are standard orchestration capabilities within the agent platform and do not involve arbitrary shell command execution or external process spawning.
  • [DATA_EXFILTRATION]: Analysis confirms the skill does not contain patterns for unauthorized data transfer. The 'Guardian Pattern' mentioned in the text is a security oversight mechanism that triggers additional audits when the agent handles sensitive materials like authentication tokens or access permissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 05:12 PM
Security Audit — agent-trust-hub — boss-advanced