agent-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for agents that process untrusted data from external sources, such as database query results and persistent memory layers. While this establishes a potential attack surface, the documentation provides extensive mitigation guidance, including structured validation loops for SQL execution, schema enforcement, and the use of 'checker nodes' to verify sibling outputs in parallel workflows before they are consumed by downstream agents.
  • Ingestion points: SQL tool results, memory retrieval, and user messages (SKILL.md, references/patterns.md).
  • Boundary markers: The skill recommends using immutable context objects and clear partitioning between the static prompt prefix and dynamic trajectories (references/patterns.md, references/kv-cache.md).
  • Capability inventory: SQL execution, tool calling, and memory management (references/patterns.md).
  • Sanitization: Implementation of pre-validation schema checks, DML blocking for safety, and post-execution sanity checks (references/patterns.md).
  • [EXTERNAL_DOWNLOADS]: The documentation references legitimate external resources for educational context, including academic papers on arXiv and open-source projects on GitHub (e.g., HKUDS/OpenHarness). These references target well-known research and service domains.
  • [COMMAND_EXECUTION]: The skill provides code snippets for executing SQL queries and managing agent subprocesses. These snippets are presented as safe design patterns, incorporating specific security measures such as read-only enforcement and timeout handling to prevent resource exhaustion or unauthorized data modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 12:11 PM
Security Audit — agent-trust-hub — agent-orchestrator