long-task-coordinator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on durable state files to maintain context across sessions, which introduces an ingestion point for untrusted data if the files are modified by external actors.
- Ingestion points: The skill's defined core loop and operating workflow (Step 3) require reading state files, such as
docs/<topic>-state.md, to recover the task status at the start of every session. - Boundary markers: The instructions do not specify the use of delimiters or instructions to ignore potential commands embedded in the state file, increasing the risk that the agent may interpret data as executable instructions.
- Capability inventory: The skill is authorized to use a wide range of sensitive tools via the
allowed-toolsconfiguration, includingBash,Write, andEdit, which could be abused if the agent is misled by injected content. - Sanitization: There are no provisions or requirements for validating the integrity or sanitizing the contents of the state files before the agent processes them.
Audit Metadata