Back to skill

Security audit

Agent Orchestrate

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only orchestration skill whose behavior fits its purpose, though users should be careful about passing one agent's output into another and about saving workflow state locally.

Install only if you want multi-agent orchestration guidance. Treat prior agent results as untrusted data, limit tools available to spawned agents, require human approval before sensitive changes or external sends, and avoid storing secrets or private task content in the example state/checkpoint files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/dependency-tree.md:88
Finding

Untrusted Agent Output Is Injected into Downstream Prompts

Content
View full analysis

Vulnerability Details

File Location: references/dependency-tree.md:88-101
Additional Locations: SKILL.md:44-53, SKILL.md:74-84, references/fan-out.md:94-98, references/pipeline.md:19-34
Vulnerability Type: Indirect prompt injection through unsanitized orchestration results
Risk Level: Medium

Vulnerable Code

references/dependency-tree.md:88-101:

python
# Spawn ready tasks
for task_name in ready:
    task = state["tasks"][task_name]
    
    # Build context from dependencies (fork pattern)
    dep_context = build_dependency_context(state, task["blockedBy"])
    full_task = f"{task['task']}\n\nContext from prior work:\n{dep_context}"
    
    sessions_spawn(task=full_task, label=task_name)
    task["status"] = "running"

save_state(state)
time.sleep(30)
update_running_status(state)

references/pipeline.md:19-34:

python
stages = [
    {"label": "stage-1-research", "task": "Research the topic: {topic}"},
    {"label": "stage-2-analyze", "task": "Analyze this research and identify key themes:\n\n{prev_result}"},
    {"label": "stage-3-write", "task": "Write a report based on this analysis:\n\n{prev_result}"},
]

prev_result = ""

for i, stage in enumerate(stages):
    # Inject previous result into task
    task = stage["task"].format(topic=topic, prev_result=prev_result)
    
    # Spawn and wait
    sessions_spawn(task=task, label=stage["label"])
    wait_for_completion(stage["label"])
    
    # Extract result for next stage
    prev_result = get_agent_result(stage["label"])

references/fan-out.md:94-98:

text
Phase 2 (Synthesis):
└── Agent 6: Synthesize all findings (fork - receives all results)

The synthesis agent gets all 5 research results injected into its context.

Technical Analysis

The documented dependency-tree, pipeline, and fan-out patterns place results produced by one agent directl ...[truncated 2722 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat every upstream result as untrusted data, including output produced by another agent.
  2. Place inherited material in an explicit, clearly delimited data section and instruct the downstream agent that content inside that section is evidence only and must never override its task or system instructions.
  3. Prefer structured schemas with allow-listed fields over concatenating free-form results into prompts. Reject malformed or unexpected fields.
  4. Add an intermediate sanitization or constrained summarization stage that identifies and removes imperative instructions, tool requests, credential requests, and attempts to alter the downstream task.
  5. Preserve provenance for every result so the downstream agent can distinguish user instructions, orchestration instructions, agent conclusions, and externally sourced quotations.
  6. Minimize the tools and permissions available to synthesis and analysis agents. Use separate, least-privilege agents for any action that changes files, invokes external services, or accesses secrets.
  7. Require explicit human approval before sensitive downstream actions, including sending data externally, modifying important files, using credentials, or executing commands.
  8. Limit the size and content types of inherited results and avoid passing complete session histories when a validated summary is sufficient.
  9. Add adversarial tests in which upstream content contains prompt-injection instructions, ensuring downstream agents ignore those instructions and continue only the declared workflow.
  10. Record and surface suspicious inherited directives rather than executing them, allowing the orchestrator or a human reviewer to quarantine affected results.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says advanced dynamic orchestration such as human-in-the-loop belongs in the cord-trees skill, implying this skill is limited to simple parallel work and basic pipelines. However, the document later includes dependency-tree, human-in-the-loop, and supervisor orchestration patterns, which go beyond the stated limited scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The heading text states this is a quick reference and directs advanced dynamic orchestration to cord-trees. Later sections actively instruct on human-in-the-loop orchestration, dependency-based scheduling, and supervisor intervention, which contradicts that scoping guidance rather than merely omitting details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes implementation guidance that reads from and writes to orchestration-state.json, which stores task details and results. The surrounding documentation does not warn users that task content and prior work context may be persisted on disk, so users may not realize their workflow data is being stored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.