dag-orchestration
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references 'Multica' (github.com/multica-ai/multica) as a conceptual framework for task lifecycle management. This is a well-known service reference and does not involve automated downloads or execution.
- [COMMAND_EXECUTION]: The orchestrator logic describes a topological sort algorithm and potential execution via a 'Task tool'. While this implies tool usage, it is restricted to the platform's native task environment and follows safety rules (R009, R010).
- [DATA_EXPOSURE]: State tracking is localized to
/tmp/.claude-dag-$PPID.jsonor/tmp/.claude-pipeline-{name}-{PPID}.json. These are standard temporary paths for process-scoped state management and do not expose sensitive credentials. - [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypass, or instruction overrides. The skill uses structured YAML for workflow definitions.
- [DYNAMIC_CONTEXT_INJECTION]: No use of the
!commandsyntax or silent load-time execution patterns was detected in the SKILL.md file.
Audit Metadata