afk-orchestrator
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The orchestrator is designed to ingest and process potentially untrusted external data, which could be used to influence its logic or the instructions it sends to sub-agents. \n
- Ingestion points: The skill reads task descriptions, specifications, Architectural Decision Records (ADRs), and detailed reports from sub-agents (
afk-slice-workerandafk-slice-reviewer) as defined inSKILL.mdandreferences/review-flow.md. \n - Boundary markers: There are no explicit instructions or delimiters defined to separate untrusted data from the core orchestration instructions, increasing the risk that the model might follow instructions embedded within the data. \n
- Capability inventory: The skill has the authority to trigger external sub-agent skills, manage Git worktrees, write state information to the local file system (
.scratch/afk-runs/), and perform verification steps using production credentials/permissions as described inreferences/review-flow.md. \n - Sanitization: The instructions do not specify any validation or sanitization steps for the content retrieved from external task definitions or sub-agent outputs. \n- [PERSISTENCE]: The skill implements a persistence mechanism to maintain access to state across orchestration sessions. \n
- Evidence:
SKILL.mdspecifies that session data and decisions should be recorded in.scratch/afk-runs/<slug>.jsonlif host-provided persistence is unavailable.
Audit Metadata