delegating-to-otto

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the astro command-line tool to drive the Otto sub-agent. This includes passing user-provided prompts as arguments to astro otto to perform data engineering tasks.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references official vendor operations such as updating the agent via astro otto update and retrieving runtime model configurations from the Astronomer Gateway.\n- [DATA_EXFILTRATION]: Although the sub-agent has the capability to interact with files, the skill explicitly describes bypass-immune safety checks within the astro tool that protect sensitive directories (e.g., ~/.ssh, ~/.aws) and environment files from unauthorized access.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 11:29 AM