skills/verstak-ai/skills/foreman/Gen Agent Trust Hub

foreman

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to manage and monitor a 'crew' of sub-agents ('doers'), which involves ingesting their reports, status updates, and inquiries. This architecture creates an indirect prompt injection surface where a sub-agent could produce output that influences the foreman's decision-making or relay logic.\n
  • Ingestion points: The foreman agent reads 'doer' reports, session states, artifact metadata, and a shared 'inquiry' queue where sub-agents post questions.\n
  • Boundary markers: There are no explicit instructions for the agent to use delimiters or sanitization techniques when processing or relaying content from the sub-agents.\n
  • Capability inventory: The foreman has the ability to launch new agent sessions, interrupt hung turns, relay instructions to sub-agents, and communicate recommendations to an 'owner' role.\n
  • Sanitization: The instructions focus on relaying reasoning and plain-word translation but do not include technical validation or sanitization of the data ingested from the agents it manages.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 01:06 PM
Security Audit — agent-trust-hub — foreman