cto-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local analysis scripts using the python and bash interpreters. These scripts (tech_debt_analyzer.py and team_scaling_calculator.py) are referenced via relative paths pointing to a 'c-level-advisor' directory structure. This is standard behavior for specialized analysis tools within a structured environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts a <plan> as user input for analysis. While this presents an attack surface for indirect prompt injection, the skill is diagnostic in nature and does not exhibit high-risk autonomous capabilities that would escalate this beyond a baseline concern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:46 PM
Security Audit — agent-trust-hub — cto-review