workflow-parallel-agents — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited workflow-parallel-agents (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Cursor creates isolated git worktrees for each agent. Each has its own:
When an agent finishes, click Apply to merge changes back.
Delegate tasks you'd otherwise put on a todo list:
@Cursor <task description># Good delegation prompt
Fix the bug where users see a 500 error when they submit the onboarding form
with a duplicate email. The error should show an inline message "Email already
in use" instead of crashing. See `app/onboarding/actions.ts` for the server
action and `app/onboarding/page.tsx` for the form.
# Bad delegation prompt
Fix the email bugInclude:
Best for:
When running many agents, configure:
Run 2-3 agents with different approaches to a hard problem:
Compare all three, pick the cleanest.
While implementing feature X locally:
features/auth/"One agent reviews for security, another for performance:
app/api/ for security issues (auth, input validation, RLS)"app/api/ for performance (N+1s, missing indexes, large payloads)"node_modules if deps differ.env by symlinking or copying to each worktreegit worktree remove <path>~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.