pstack-omp
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a system where sub-agents ingest external data, creating a potential surface for indirect prompt injection. The skill incorporates the following architectural safety measures:\n * Ingestion points: Sub-agents such as 'scout' and 'librarian' ingest repository code and external documentation as described in SKILL.md.\n * Boundary markers: Task isolation is enforced through 'isolated: true' workspace flags and standalone task briefs.\n * Capability inventory: Agents possess repository write capabilities and inter-agent communication via the 'hub' tool, but are strictly forbidden from spawning further sub-agents.\n * Sanitization: The protocol requires the root agent to perform independent verification of all outputs and behavioral proofs.\n- [SAFE]: The skill instructions and role definitions were analyzed for malicious patterns. No evidence of credential harvesting, unauthorized network communication, or obfuscated malicious code was found. The use of platform-specific URI schemes and tools is consistent with the stated purpose of agent orchestration.
Audit Metadata