boss-advanced
Pass
Audited by Gen Agent Trust Hub on Jun 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively contains organizational and procedural instructions for AI agent coordination and does not execute any malicious code or exfiltrate data.
- [PROMPT_INJECTION]: The skill incorporates defensive prompt engineering via a '6-Section Delegation Prompt Template'. This template uses explicit boundary markers (e.g., MUST DO, MUST NOT DO, EXPECTED OUTCOME) to constrain sub-agent behavior and prevent instruction drift or indirect injection from sub-agent outputs.
- [COMMAND_EXECUTION]: The skill defines logic for spawning sub-agents and invoking internal skills (e.g., 'team', 'gstack-sprint'). These are standard orchestration capabilities within the agent platform and do not involve arbitrary shell command execution or external process spawning.
- [DATA_EXFILTRATION]: Analysis confirms the skill does not contain patterns for unauthorized data transfer. The 'Guardian Pattern' mentioned in the text is a security oversight mechanism that triggers additional audits when the agent handles sensitive materials like authentication tokens or access permissions.
Audit Metadata