coordinate
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent ingests external data such as GitHub issues, PRDs, and project documentation to generate 'dispatch briefs' for sub-agents. This workflow presents an attack surface for indirect prompt injection if malicious instructions are embedded in the external project data.
- Ingestion points: The agent reads issues, Product Requirement Documents (PRDs), and project laws (CLAUDE.md, AGENTS.md, etc.) as described in Step 1 (SKILL.md).
- Boundary markers: The instructions do not explicitly require the use of delimiters or protective headers when incorporating external task descriptions into the briefs generated in Step 3.
- Capability inventory: The coordinator agent has the capability to create integration branches, dispatch sub-agents using the
Agentcall, perform code edits for 'nit-fixing', and merge pull requests (SKILL.md). - Sanitization: There are no explicit instructions to sanitize or escape content from issues or PRDs before they are passed to sub-agents.
- Mitigation: The risk is significantly mitigated by Step 5 ('Present the execution plan'), which requires the agent to present all planned briefs to a human user for review and approval before any sub-agents are dispatched.
Audit Metadata