ops-herdr

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill heavily uses subprocess.run (specifically in scripts/ops_herdr_core.py within the run_herdr function) to execute the herdr binary. This is the intended primary purpose of the skill to act as a CLI wrapper. The commands are constructed using lists (argv) which mitigates standard shell injection risks.
  • [DATA_EXPOSURE]: The skill manages environment variables via parse_env_options and herdr_env, but these are used for session management and passing configuration to the sub-agents. It does not attempt to read sensitive system files like SSH keys or cloud credentials.
  • [REMOTE_CODE_EXECUTION]: While the skill can start various AI agents (e.g., 'codex', 'claude') inside Herdr panes, it does so by invoking the local herdr binary. It does not perform arbitrary remote code downloads or 'curl | bash' patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface in scripts/cli.py and scripts/ops_herdr_loops.py where it reads tasks and work orders to send prompts to agents. However, it implements boundary markers (e.g., 'TAU_CREATOR_RECEIPT_WRITTEN') and expects structured JSON receipts to validate sub-agent work, which reduces the risk of accidental instruction following from untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ops-herdr