align
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill generates shell scripts in
.align/reviews/intended for review playback. These scripts call local utilities likecurlto interact with a localhost model proxy (localhost:4001) or invoke other skills such as$askand$dogpileviaskills/*/run.sh. The execution is restricted to internal tooling and local APIs. - [EXTERNAL_DOWNLOADS]: The
prepare-reviewcommand createscurlcommands targetinglocalhost:4001/v1/chat/completions. This is used for local model critique using thescillmparticipant and does not involve untrusted remote servers. - [DATA_EXPOSURE]: The skill reads and writes state information to a
.aligndirectory. While it processes data from other participants (human, project_agent), it does not access sensitive system files like SSH keys or AWS credentials. - [PROMPT_INJECTION]: The skill uses structured data and explicit status flags (
ready_for_execution) to gate downstream agent actions. While it incorporates participant responses into an alignment brief, the purpose of the skill itself is to resolve contradictions and clarify goals, providing a resilience layer against ambiguous or conflicting instructions.
Audit Metadata