agent-decision-receipts

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the openagentontology library (optionally with [pq] for post-quantum algorithms) to handle cryptographic signing. This is a functional dependency for the skill's stated purpose of minting receipts and is documented for the operator to install.
  • [SAFE]: The manifest building process in scripts/build_action_manifest.py uses the inputs_hash field to store a SHA-256 hash of operation parameters rather than cleartext. This follow security best practices by preventing the accidental exposure of sensitive data in audit logs.
  • [SAFE]: The provided Python script is designed to be minimal and secure, using only standard library modules and performing strict ASCII validation to ensure that cryptographic evidence is reproducible across different environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 02:44 PM
Security Audit — agent-trust-hub — agent-decision-receipts