orchestrating-swarms
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for spawning subagents with
Bashtool access to perform system tasks, such asgitoperations and package installation.- [EXTERNAL_DOWNLOADS]: The documentation recommends installing well-known utilities liketmuxandit2(viauvorpip) to manage agent processes in different terminal environments.- [PROMPT_INJECTION]: The skill demonstrates patterns where output from one agent (e.g., research results) is interpolated directly into the prompt of another agent. This creates a surface for indirect prompt injection if the source data contains malicious instructions.- [DATA_EXFILTRATION]: The skill includes examples of agents performing security audits and searching for sensitive files (e.g., 'auth files'), which involves reading local configuration. This is consistent with the skill's stated purpose of automated code review.
Audit Metadata