software-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill configures several sub-agents (bpm, art, audio, qa) to use the Bash tool for software development activities, including script execution, asset processing, and running automated tests.
  • [EXTERNAL_DOWNLOADS]: The skill identifies the author's GitHub repository (hairyf/skills) as the source for its scripts and references a migration tool from the official openai/skills repository.
  • [REMOTE_CODE_EXECUTION]: The orchestration agent (bpm) is designed to dynamically spawn and manage sub-agents using the Agent tool to handle specialized project roles.
  • [PROMPT_INJECTION]: The skill ingests user feedback and project requirements through the design agent to generate specifications, which subsequently drive the actions of implementation agents. It includes user review gates and verification steps as boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 01:13 AM
Security Audit — agent-trust-hub — software-engineering