orchestrator-mode
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: As an orchestrator, the skill aggregates findings and summaries from subagents. This architectural pattern represents an attack surface for indirect prompt injection, as subagents may ingest untrusted data from the repository or external sources and relay it to the coordinator. \n
- Ingestion points: The coordinator thread ingests compact reports, worker artifacts, and handoff summaries from subagents (
SKILL.md). \n - Boundary markers: The instructions do not specify explicit delimiters or markers to isolate worker-provided content from system instructions. \n
- Capability inventory: The skill manages subagent spawning, task resumption, and coordinated file/git operations across multiple workers (
SKILL.md,references/reference.md). \n - Sanitization: The workflow relies on workers providing concise summaries and artifact indices, but does not explicitly detail sanitization of these outputs before processing by the main thread. \n- [COMMAND_EXECUTION]: The coordination logic involves executing shell-based commands through subagents to manage project state and parallel workflows. \n
- Evidence: The workflow for parallel writes utilizes
git worktree addto create isolated environments for concurrent tasks, ensuring that implementation work is performed on specific branches and base commits (references/reference.md).
Audit Metadata