autogen-tool-orchestration
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation, process guidelines, and code templates designed to implement secure tool execution environments. No malicious patterns, such as obfuscated code, persistence mechanisms, or unauthorized privilege escalation, were detected.
- [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection risks by defining an architecture where the model is not trusted for authorization. It mandates that all tool calls are validated and authorized by an execution adapter using principal identities resolved from the request context rather than model output.
- [CREDENTIALS_UNSAFE]: The skill explicitly enforces secure secret management. It prohibits hardcoding credentials, requires their injection at deployment time, and mandates the redaction of PII and secrets from all logs and audit records.
- [DATA_EXFILTRATION]: No unauthorized network operations or data exfiltration patterns were found. The tool registry is restricted per-agent, ensuring that agents only have access to the specific tools defined in the architecture.
Audit Metadata