orchestrating-subagents

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong instructional language to define the 'orchestrator' persona and enforce strict operational rules. These instructions are focused on task decomposition and sub-agent management and do not attempt to bypass system safety constraints or extract internal prompt data.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the creation of sub-agent tasks and dynamic workflows. While this involves the execution of generated logic, it relies on built-in platform features (Claude Code sub-agents, Codex) and requires user opt-in for large-scale operations, following established development patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references Context7 for documentation retrieval via MCP tools and provides installation instructions using the standard skills CLI. All external links point to official documentation or well-known service providers.
  • [DATA_EXFILTRATION]: No unauthorized data transmission or credential harvesting patterns were identified. Communication is restricted to the agent's context and defined sub-agent boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The orchestrator ingests project data (repo layout, library versions) to generate sub-agent briefs. This represents a standard data processing surface; however, the skill includes explicit 'Verify, don't trust' instructions and integration checks to mitigate risks associated with processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 10:05 PM
Security Audit — agent-trust-hub — orchestrating-subagents