afa-scale

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a coordination and routing framework for a Direct-to-Consumer (DTC) business system. It does not contain shell commands, script execution, or network exfiltration logic.
  • [DATA_EXPOSURE]: The skill identifies internal project files such as products.md and brand-brain as data sources for business audits. These are domain-specific configuration files and do not include system-level sensitive information like SSH keys or API tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user_request data from a parent 'Hub' module. While it lacks explicit sanitization instructions for this input, its capabilities are limited to selecting internal routing paths (afa-ops, afa-expand) and generating structured YAML reports. No dangerous primitives (e.g., code execution or external network calls) are exposed to the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 12:58 AM
Security Audit — agent-trust-hub — afa-scale