skills/grahama1970/agent-skills/align/Gen Agent Trust Hub

align

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates shell scripts in .align/reviews/ intended for review playback. These scripts call local utilities like curl to interact with a localhost model proxy (localhost:4001) or invoke other skills such as $ask and $dogpile via skills/*/run.sh. The execution is restricted to internal tooling and local APIs.
  • [EXTERNAL_DOWNLOADS]: The prepare-review command creates curl commands targeting localhost:4001/v1/chat/completions. This is used for local model critique using the scillm participant and does not involve untrusted remote servers.
  • [DATA_EXPOSURE]: The skill reads and writes state information to a .align directory. While it processes data from other participants (human, project_agent), it does not access sensitive system files like SSH keys or AWS credentials.
  • [PROMPT_INJECTION]: The skill uses structured data and explicit status flags (ready_for_execution) to gate downstream agent actions. While it incorporates participant responses into an alignment brief, the purpose of the skill itself is to resolve contradictions and clarify goals, providing a resilience layer against ambiguous or conflicting instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — align