skills/syn54x/skills/coordinate/Gen Agent Trust Hub

coordinate

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent ingests external data such as GitHub issues, PRDs, and project documentation to generate 'dispatch briefs' for sub-agents. This workflow presents an attack surface for indirect prompt injection if malicious instructions are embedded in the external project data.
  • Ingestion points: The agent reads issues, Product Requirement Documents (PRDs), and project laws (CLAUDE.md, AGENTS.md, etc.) as described in Step 1 (SKILL.md).
  • Boundary markers: The instructions do not explicitly require the use of delimiters or protective headers when incorporating external task descriptions into the briefs generated in Step 3.
  • Capability inventory: The coordinator agent has the capability to create integration branches, dispatch sub-agents using the Agent call, perform code edits for 'nit-fixing', and merge pull requests (SKILL.md).
  • Sanitization: There are no explicit instructions to sanitize or escape content from issues or PRDs before they are passed to sub-agents.
  • Mitigation: The risk is significantly mitigated by Step 5 ('Present the execution plan'), which requires the agent to present all planned briefs to a human user for review and approval before any sub-agents are dispatched.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:54 PM
Security Audit — agent-trust-hub — coordinate