documents-orchestrator
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to dynamically load sub-skill definitions by reading files from paths constructed using variable spoke names:
~/.agents/skill-clusters/skills/<spoke-name>/SKILL.md. This behavior involves the agent accessing the filesystem to load new instructions at runtime based on computed paths. - [PROMPT_INJECTION]: The skill functions as a router for document-related tasks, which introduces a surface for indirect prompt injection. Maliciously crafted document tasks or file contents could attempt to manipulate the routing logic to cause the agent to load files from unintended locations.
- Ingestion points: External document content and user-provided task descriptions used for classification.
- Boundary markers: None identified in the instructions to separate untrusted data from the orchestrator's decision-making process.
- Capability inventory: Filesystem read access for loading
SKILL.mdfiles from the sub-skill directory structure. - Sanitization: There are no explicit instructions for the agent to validate the resulting
<spoke-name>against the defined list of safe spokes before attempting the file read operation.
Audit Metadata