skills/a-canary/arc-skills/pipeliner/Gen Agent Trust Hub

pipeliner

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a workflow involving the execution of TypeScript modules via a shell environment and system cron. This is the intended functionality for managing automated pipelines.
  • [EXTERNAL_DOWNLOADS]: Mentions the installation and use of the pi-pipeliner npm package as a dependency for the framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by instructing the agent to read configuration and API details from local files (~/repos/pipeliner/README.md) and to generate executable modules.
  • Ingestion points: ~/repos/pipeliner/README.md (SKILL.md)
  • Boundary markers: Absent. The agent is instructed to read the file directly for API details.
  • Capability inventory: Shell execution, npm package interaction, and invocation of the claude CLI tool.
  • Sanitization: No specific sanitization or validation logic is mentioned for the content read from the repository documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:39 AM
Security Audit — agent-trust-hub — pipeliner