agents-swarm-orchestration

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an orchestration framework where a lead agent processes and synthesizes data from multiple sub-workers. While this creates a potential attack surface for indirect injection, the skill includes comprehensive mitigations: it mandates the use of structured JSON schemas for all worker reports to prevent prose from being interpreted as instructions, requires explicit 'owned_files' and 'do_not_touch' boundary markers, and provides specific rules for sanitizing external dependency data. Ingestion occurs via worker reports and repository scans, while capabilities are scoped to specific tools like 'Bash' and 'Edit' within authorized workspaces.
  • [EXTERNAL_DOWNLOADS]: The documentation includes references to official platform documentation (Anthropic, OpenAI), research papers (Ye & Tan, Tran & Kiela), and established community repositories (LangGraph, CrewAI). All external links point to well-known, reputable services and are used for instructional support.
  • [COMMAND_EXECUTION]: The skill provides examples of shell-based orchestration (e.g., 'claude -p', 'parallel') and includes a shell-script recipe demonstrating wave dispatch. These are pedagogical examples for setting up local workflows and do not contain unauthorized or malicious logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — agents-swarm-orchestration