claude-devfleet

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill's orchestration workflow creates an indirect prompt injection surface by passing user-supplied instructions to sub-agents.
  • Ingestion points: User prompts provided to the plan_project and create_mission tools in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions to sub-agents to disregard instructions embedded within mission prompts.
  • Capability inventory: Spawned agents are described as having 'full tooling' access within isolated git worktrees.
  • Sanitization: No validation or sanitization of the input prompt parameters is documented.
  • [NO_CODE]: The skill consists entirely of markdown documentation and tool definitions with no included scripts, binaries, or dynamic code execution logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 07:43 AM
Security Audit — agent-trust-hub — claude-devfleet