pick-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a design-time advisor for agent execution topology. It analyzes task requirements and decomposes work into steps without performing operations that modify the host system or access external networks. It uses a logic-based framework to recommend patterns like routing, voting, and orchestrator-worker models based on Anthropic's established multi-agent system research.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. While the documentation mentions 'Workflow' mechanisms involving deterministic JS control flow (loops, conditionals), these are described as environmental primitives for agent orchestration rather than vectors for loading or executing untrusted external scripts.
  • [DATA_EXFILTRATION]: The skill does not possess network-capable tools or demonstrate patterns of data exfiltration. Its operations are confined to reading local configuration and providing architectural design designs to the user or agent orchestrator.
  • [OBFUSCATION]: Analysis of the skill instructions and reference materials found no evidence of hidden characters, Base64-encoded payloads, homoglyph attacks, or other obfuscation techniques designed to evade security scanning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 09:07 AM
Security Audit — agent-trust-hub — pick-workflow