gpt-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to "research this codebase" and "inspect artifacts," which creates an ingestion surface for untrusted data that could contain malicious instructions.
  • Ingestion points: Codebase contents and build artifacts processed during the orchestration workflow (referenced in SKILL.md).
  • Boundary markers: The skill does not explicitly define delimiters or specific "ignore instructions" tags for the data being researched.
  • Capability inventory: The orchestration fleet has capabilities related to system build, integration, verification, and managing database edges.
  • Sanitization: The skill advises the agent to "inspect artifacts rather than trusting summaries" and perform "evidence-backed disposition," which serves as a manual verification step.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 10:57 AM
Security Audit — agent-trust-hub — gpt-orchestration