asta-flows

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The init workflow facilitates the installation of the beads (bd) and jq command-line tools. These are sourced from well-known package managers or the project's official repository on GitHub (github.com/gastownhall/beads) to ensure the execution environment is properly configured.
  • [COMMAND_EXECUTION]: The skill executes several internal bash scripts (e.g., epic-root.sh, summary-check.sh, validate-output.sh) to automate state management and structural validation. These scripts utilize standard utilities to maintain the integrity of the research graph.
  • [DATA_EXFILTRATION]: To support cross-machine collaboration, the skill provides instructions for synchronizing the research database with the project's git remote (origin) using the dolt data engine. This is the primary intended mechanism for state persistence and sharing.
  • [PROMPT_INJECTION]: The skill ingests research data from mission.md and previous task outputs. Although this constitutes a surface for indirect prompt injection, the risk is mitigated by the skill's reliance on structured JSON schemas and automated structural validation for all task outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 08:01 AM
Security Audit — agent-trust-hub — asta-flows