claude-devfleet
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill's orchestration workflow creates an indirect prompt injection surface by passing user-supplied instructions to sub-agents.
- Ingestion points: User prompts provided to the
plan_projectandcreate_missiontools inSKILL.md. - Boundary markers: There are no explicit delimiters or instructions to sub-agents to disregard instructions embedded within mission prompts.
- Capability inventory: Spawned agents are described as having 'full tooling' access within isolated git worktrees.
- Sanitization: No validation or sanitization of the input prompt parameters is documented.
- [NO_CODE]: The skill consists entirely of markdown documentation and tool definitions with no included scripts, binaries, or dynamic code execution logic.
Audit Metadata