skills/carlitose/agent-skills/wizard/Gen Agent Trust Hub

wizard

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill facilitates the creation of Bash scripts. It includes specific safeguards, such as a 'fixture mode' for safe validation and instructions for the agent to verify script integrity using static analysis tools instead of direct execution.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The provided template contains functions to persist data to environment files and GitHub secrets. These functions are protected by environment-level opt-ins and mandatory interactive confirmation prompts, ensuring the human operator retains full control.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user input to define script stages. The potential for malicious instruction injection is mitigated by the 'disable-model-invocation' constraint and the necessity for human oversight and manual execution of the final authored script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 05:26 PM
Security Audit — agent-trust-hub — wizard