ops-herdr
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill heavily uses
subprocess.run(specifically inscripts/ops_herdr_core.pywithin therun_herdrfunction) to execute theherdrbinary. This is the intended primary purpose of the skill to act as a CLI wrapper. The commands are constructed using lists (argv) which mitigates standard shell injection risks. - [DATA_EXPOSURE]: The skill manages environment variables via
parse_env_optionsandherdr_env, but these are used for session management and passing configuration to the sub-agents. It does not attempt to read sensitive system files like SSH keys or cloud credentials. - [REMOTE_CODE_EXECUTION]: While the skill can start various AI agents (e.g., 'codex', 'claude') inside Herdr panes, it does so by invoking the local
herdrbinary. It does not perform arbitrary remote code downloads or 'curl | bash' patterns. - [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface in
scripts/cli.pyandscripts/ops_herdr_loops.pywhere it reads tasks and work orders to send prompts to agents. However, it implements boundary markers (e.g., 'TAU_CREATOR_RECEIPT_WRITTEN') and expects structured JSON receipts to validate sub-agent work, which reduces the risk of accidental instruction following from untrusted data.
Audit Metadata