Back to skill

Security audit

Agent Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for multi-agent task orchestration, but it gives broad autonomous agent, file-copying, command, and retention authority without enough user-control safeguards.

Install only if you intentionally want a skill that coordinates autonomous sub-agents. Before using it, choose a dedicated workspace, avoid giving it sensitive files unless necessary, confirm which files may be copied, require approval before Bash or write-heavy subtasks, and decide whether agent workspaces should be archived or deleted after completion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/communication-protocol.md (reported line 72)May include surrounding context.

md
# Task: {TASK_NAME}

## Objective
{Clear statement of what needs to be accomplished}

## Context
{Background information relevant to the task}

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The mandatory trigger list includes very broad phrases such as 'orchestrate', 'decompose task', and 'delegate tasks', which can cause the skill to activate in routine conversations where the user did not intend autonomous multi-agent behavior. In this skill, unintended activation is more dangerous because activation can lead to spawning sub-agents, creating workspaces, and copying files, expanding the action surface beyond a normal single-agent skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs the operator to create sub-agent workspaces and generate per-agent SKILL.md files, but it does not clearly warn that the process will create directories and persistent files on disk. In the context of an orchestration skill, that omission is risky because users may unknowingly authorize broad filesystem changes and the creation of autonomous agent instructions that persist beyond the immediate task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The dispatch phase tells the orchestrator to copy required input files into each agent inbox without clearly warning the user that their files may be duplicated across multiple agent workspaces. This increases data exposure risk, especially if sensitive files are propagated to several sub-agents or archived later, multiplying the number of locations where confidential content resides.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The dissolution step mentions archiving workspaces and cleaning up temporary files, but it does not clearly warn users that agent artifacts may be retained or moved into archives instead of being deleted. In a multi-agent system that may handle copied inputs, generated instructions, and outputs, unclear archival behavior can lead to unintended long-term retention of sensitive material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Code Agent template explicitly authorizes file writes and Bash command execution, including running tests and fixing issues, but provides no safety constraints, approval requirements, or user-visible warning about the side effects of those actions. In an agent-orchestration skill that dynamically spawns sub-agents, this increases the chance that generated agents will perform unintended filesystem changes or execute risky commands based only on task input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.