skills/go7hic/ystack/arena/Gen Agent Trust Hub

arena

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a structured methodology for managing multiple AI agents working in parallel. No malicious patterns, exfiltration attempts, or obfuscation techniques were detected.
  • [DATA_EXPOSURE]: The skill instructs the agent to use dedicated local directories (e.g., /tmp/arena-<slug>/) for isolating candidate outputs. This is a standard development practice to maintain state separation and does not involve accessing sensitive system files or credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading and synthesizing output from other AI agents ('candidates'). This introduces an inherent surface for indirect prompt injection if a candidate produces adversarial content. However, the skill explicitly mitigates this risk by instructing the lead agent to 'read every candidate end to end,' 'score each candidate against the rubric,' and 'fold each graft in by hand' rather than mechanical pasting. It also includes a mandatory 'Verify' phase to ensure the final artifact is correct.
  • [COMMAND_EXECUTION]: The skill references platform-specific capability verbs like 'implement', 'parallel', and 'verify'. These are used within the intended scope of an Agent Skills environment for task automation and do not represent unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:06 PM
Security Audit — agent-trust-hub — arena