orchestrating-agent-delegation

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill does not contain any injection attempts. Instead, it provides a structured prompt template for subagents that includes explicit security constraints, such as instructions to not commit code, not create unnecessary files, and respect permission classifiers.
  • [DATA_EXFILTRATION]: No network operations or data transmission patterns were detected. The skill specifically notes that role discovery and configuration are handled through local directory reading rather than network calls or external registries.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of trusting processed agent data and implements a 'trust-but-verify' mitigation strategy. It instructs the user to ignore agent-generated summaries in favor of inspecting actual file diffs and running independent test suites to verify results.
  • [COMMAND_EXECUTION]: The skill provides instructional frameworks for human-led orchestration and does not include scripts or instructions that trigger automated shell command execution or system modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:27 PM
Security Audit — agent-trust-hub — orchestrating-agent-delegation