skills/borghei/claude-skills/agenthub/Gen Agent Trust Hub

agenthub

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a workflow orchestration system using localized state management. All scripts (dag_analyzer.py, session_manager.py, board_manager.py, result_ranker.py) utilize standard Python libraries for JSON processing, data structure manipulation, and CLI argument parsing.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a platform for processing data between agents, which inherently involves an indirect prompt injection surface. However, the design emphasizes security best practices including explicit input/output contracts, quality gates, and structured evaluation thresholds to mitigate the risk of malicious or low-quality data propagating through the workflow.
  • Ingestion points: scripts/session_manager.py (ingests agent outputs via --output-data) and scripts/result_ranker.py (processes completed agent outputs for ranking).
  • Boundary markers: The skills/eval.md sub-skill defines explicit quality thresholds and rubric-based evaluation to validate outputs before they flow to downstream agents.
  • Capability inventory: The orchestration scripts are limited to data analysis and local file state management; they do not contain functions for network requests, subprocess spawning, or dynamic code evaluation.
  • Sanitization: The system relies on JSON schema validation and scoring rubrics to ensure data integrity during the merge and synthesis phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 08:34 PM
Security Audit — agent-trust-hub — agenthub