foreman
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to manage and monitor a 'crew' of sub-agents ('doers'), which involves ingesting their reports, status updates, and inquiries. This architecture creates an indirect prompt injection surface where a sub-agent could produce output that influences the foreman's decision-making or relay logic.\n
- Ingestion points: The foreman agent reads 'doer' reports, session states, artifact metadata, and a shared 'inquiry' queue where sub-agents post questions.\n
- Boundary markers: There are no explicit instructions for the agent to use delimiters or sanitization techniques when processing or relaying content from the sub-agents.\n
- Capability inventory: The foreman has the ability to launch new agent sessions, interrupt hung turns, relay instructions to sub-agents, and communicate recommendations to an 'owner' role.\n
- Sanitization: The instructions focus on relaying reasoning and plain-word translation but do not include technical validation or sanitization of the data ingested from the agents it manages.
Audit Metadata