advisor-orchestrator-worker

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill operates by executing external binaries such as agy (Antigravity), claude, jq, and perl via bash subshells to manage the workflow between the orchestrator, workers, and advisor.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests and processes untrusted data generated by external worker models.
  • Ingestion points: Worker results are read from output files in SKILL.md during the 'Verify' and 'Synthesize' phases.
  • Boundary markers: The skill uses a 'stateless brief' format defined in references/worker-brief.md to isolate tasks, but it lacks rigorous technical sanitization of model outputs.
  • Capability inventory: The orchestrator has access to network operations (curl), file system writes, and broad shell command execution.
  • Sanitization: While the API fallbacks in references/fallbacks.md use jq --rawfile to safely handle text, the primary execution path lacks similar safety measures for CLI calls.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external CLI tools and performs network requests to official Google and Anthropic API endpoints for model inference fallbacks.
  • [COMMAND_EXECUTION]: The worker dispatch logic in SKILL.md uses the pattern $(cat "$brief") inside double quotes for a shell command argument. This implementation is vulnerable to shell command substitution if the brief file content—which may be influenced by previous worker outputs—contains executable shell tokens like backticks or dollar-sign expressions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 06:45 AM
Security Audit — agent-trust-hub — advisor-orchestrator-worker