agent-status

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to manage observability for agent workflows. It performs file operations restricted to the project directory (specifically within the .plan-iterate/ folder) to store status artifacts.
  • [COMMAND_EXECUTION]: The skill provides a CLI interface (run.sh wrapping scripts/cli.py) for the agent to update its status. These commands are local, intended for state management, and do not involve shell injection vulnerabilities.
  • [DATA_EXPOSURE]: The skill manages internal state data (status.json, events.jsonl). Analysis of the source code confirms that it does not access sensitive system paths (e.g., SSH keys, AWS credentials) or environment variables containing secrets.
  • [SAFE]: The HTML generation logic in scripts/update_status.py uses html.escape() for all user-controlled or agent-controlled strings before interpolating them into the STATUS.html template. This effectively mitigates the risk of XSS if the status page is viewed in a browser. The client-side refresh logic in the HTML template uses textContent for DOM updates, which is a secure practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — agent-status