documents-orchestrator

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to dynamically load sub-skill definitions by reading files from paths constructed using variable spoke names: ~/.agents/skill-clusters/skills/<spoke-name>/SKILL.md. This behavior involves the agent accessing the filesystem to load new instructions at runtime based on computed paths.
  • [PROMPT_INJECTION]: The skill functions as a router for document-related tasks, which introduces a surface for indirect prompt injection. Maliciously crafted document tasks or file contents could attempt to manipulate the routing logic to cause the agent to load files from unintended locations.
  • Ingestion points: External document content and user-provided task descriptions used for classification.
  • Boundary markers: None identified in the instructions to separate untrusted data from the orchestrator's decision-making process.
  • Capability inventory: Filesystem read access for loading SKILL.md files from the sub-skill directory structure.
  • Sanitization: There are no explicit instructions for the agent to validate the resulting <spoke-name> against the defined list of safe spokes before attempting the file read operation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 04:09 PM