dag-orchestration

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references 'Multica' (github.com/multica-ai/multica) as a conceptual framework for task lifecycle management. This is a well-known service reference and does not involve automated downloads or execution.
  • [COMMAND_EXECUTION]: The orchestrator logic describes a topological sort algorithm and potential execution via a 'Task tool'. While this implies tool usage, it is restricted to the platform's native task environment and follows safety rules (R009, R010).
  • [DATA_EXPOSURE]: State tracking is localized to /tmp/.claude-dag-$PPID.json or /tmp/.claude-pipeline-{name}-{PPID}.json. These are standard temporary paths for process-scoped state management and do not expose sensitive credentials.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play bypass, or instruction overrides. The skill uses structured YAML for workflow definitions.
  • [DYNAMIC_CONTEXT_INJECTION]: No use of the !command syntax or silent load-time execution patterns was detected in the SKILL.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:58 PM
Security Audit — agent-trust-hub — dag-orchestration