coordinate-team
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from project issues, PRDs, and documentation (SKILL.md Step 1) to create dispatch briefs for teammates. This creates an attack surface where instructions embedded in issues could influence teammate agents. However, the skill provides strong mitigations via mandatory plan gating (Step 7) and a dual-prong review process (Step 8) that requires the Lead agent to verify all work before integration.
- [COMMAND_EXECUTION]: The skill utilizes the local
agentCLI tool to perform automated standards and specification reviews (SKILL.md Step 8). The command is executed in a restricted 'ask' mode which prevents the review tool from making unauthorized writes to the codebase during the evaluation phase.
Audit Metadata