gpt-orchestration
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions direct the agent to "research this codebase" and "inspect artifacts," which creates an ingestion surface for untrusted data that could contain malicious instructions.
- Ingestion points: Codebase contents and build artifacts processed during the orchestration workflow (referenced in
SKILL.md). - Boundary markers: The skill does not explicitly define delimiters or specific "ignore instructions" tags for the data being researched.
- Capability inventory: The orchestration fleet has capabilities related to system build, integration, verification, and managing database edges.
- Sanitization: The skill advises the agent to "inspect artifacts rather than trusting summaries" and perform "evidence-backed disposition," which serves as a manual verification step.
Audit Metadata