agent-queen-coordinator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs sovereign and authoritative role-play instructions that mandate the agent to 'establish dominance hierarchy' and 'write sovereign status'. It specifically includes an 'Emergency Mode' which instructs the agent to assume 'absolute authority' and 'bypass consensus', which are patterns used to override standard operational constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to orchestrate and process information from a variety of sub-agents including scouts, workers, and a collective intelligence unit, creating a vulnerability surface for malicious instructions embedded in sub-agent reports.
  • Ingestion points: Processes results from workers, reconnaissance from scouts, and strategic advice from the collective intelligence agent.
  • Boundary markers: The instructions lack boundary markers or explicit delimiters to prevent the coordinator from executing instructions potentially embedded in data received from these external agents.
  • Capability inventory: The skill utilizes the mcp__claude-flow__memory_usage tool to store and share directives, resource allocations, and health reports across the swarm.
  • Sanitization: There is no evidence of sanitization or validation routines for data ingested from other agents before it is stored in the shared hive memory namespace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-queen-coordinator