orchestrating-swarms

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for spawning subagents with Bash tool access to perform system tasks, such as git operations and package installation.- [EXTERNAL_DOWNLOADS]: The documentation recommends installing well-known utilities like tmux and it2 (via uv or pip) to manage agent processes in different terminal environments.- [PROMPT_INJECTION]: The skill demonstrates patterns where output from one agent (e.g., research results) is interpolated directly into the prompt of another agent. This creates a surface for indirect prompt injection if the source data contains malicious instructions.- [DATA_EXFILTRATION]: The skill includes examples of agents performing security audits and searching for sensitive files (e.g., 'auth files'), which involves reading local configuration. This is consistent with the skill's stated purpose of automated code review.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 05:36 PM