advisor-orchestrator-worker
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill operates by executing external binaries such as
agy(Antigravity),claude,jq, andperlvia bash subshells to manage the workflow between the orchestrator, workers, and advisor. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests and processes untrusted data generated by external worker models.
- Ingestion points: Worker results are read from output files in
SKILL.mdduring the 'Verify' and 'Synthesize' phases. - Boundary markers: The skill uses a 'stateless brief' format defined in
references/worker-brief.mdto isolate tasks, but it lacks rigorous technical sanitization of model outputs. - Capability inventory: The orchestrator has access to network operations (
curl), file system writes, and broad shell command execution. - Sanitization: While the API fallbacks in
references/fallbacks.mdusejq --rawfileto safely handle text, the primary execution path lacks similar safety measures for CLI calls. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of external CLI tools and performs network requests to official Google and Anthropic API endpoints for model inference fallbacks.
- [COMMAND_EXECUTION]: The worker dispatch logic in
SKILL.mduses the pattern$(cat "$brief")inside double quotes for a shell command argument. This implementation is vulnerable to shell command substitution if the brief file content—which may be influenced by previous worker outputs—contains executable shell tokens like backticks or dollar-sign expressions.
Audit Metadata