meta-agent

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill documentation and reference files contain no executable code, network requests, or unauthorized access to sensitive files. All templates and guidelines provided are consistent with their stated purpose of helping developers scaffold OpenCode components.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user requirements to generate code and instruction sets. While this creates a potential attack surface for indirect prompt injection, it is considered a functional part of the skill's purpose as a scaffolding tool.
  • Ingestion points: User requests for generating OpenCode components (commands, skills, plugins) described in SKILL.md.
  • Boundary markers: The reference templates provided in component-templates.mdx do not include specific delimiters or 'ignore' instructions for user-provided data.
  • Capability inventory: The skill instructions in SKILL.md and paths-and-installation.mdx indicate capabilities for creating and updating files at specific project paths.
  • Sanitization: There is no evidence of specific input validation or escaping mechanisms within the provided templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 04:35 AM
Security Audit — agent-trust-hub — meta-agent