skills/affaan-m/ecc/orch-pipeline/Gen Agent Trust Hub

orch-pipeline

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its ingestion of external data.\n- Ingestion points: Phase 0 (intake of external design documents) and Phase 1 (GitHub search results and external registry data).\n- Boundary markers: Not explicitly defined in the pipeline metadata, though human review is required before execution.\n- Capability inventory: File system modification, code execution (TDD), and git commit operations.\n- Sanitization: The skill relies on human oversight rather than automated sanitization to validate ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 12:55 AM
Security Audit — agent-trust-hub — orch-pipeline