fable-orchestrate

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a workflow for delegation to subagents using standard platform tools and configurations. It does not exhibit any malicious patterns such as credential theft, data exfiltration, or unauthorized command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from subagents, which may indirectly include content from untrusted external sources like code repositories.
  • Ingestion points: Task reports and verification outputs from subagents in SKILL.md.
  • Boundary markers: None explicitly defined in the instructions for separating subagent content.
  • Capability inventory: Uses the Agent tool and herdr skill to perform code modifications and test execution.
  • Sanitization: Relies on logical verification against criteria without technical sanitization or escaping mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 01:01 PM
Security Audit — agent-trust-hub — fable-orchestrate