j5ik2o-takt-optimizer

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages the Bash tool to execute standard development commands such as git for version control analysis, gh for interacting with GitHub pull requests and issues, and terraform for infrastructure validation. These commands are integral to its function as a developer-oriented agent skill.
  • [COMMAND_EXECUTION]: As noted in SKILL.md, the skill includes a local script validate-takt-files.sh designed to verify the structure and validity of generated TAKT workflow files.
  • [EXTERNAL_DOWNLOADS]: Research workflows (research.yaml) utilize WebSearch and WebFetch tools to retrieve external data. The skill mitigates risks by including specific instructions in research-dig.md that command the agent to prioritize trusted sources and strictly avoid downloading executable files.
  • [SAFE]: The provided configuration examples (config.yaml) contain placeholders for API keys (e.g., sk-ant-...). These strings are clearly identifiable as non-functional examples and do not expose actual credentials.
  • [SAFE]: The skill demonstrates a strong security posture by incorporating comprehensive security review facets (security-reviewer persona and security.md policy) that define rigorous checks for injection vulnerabilities, authentication flaws, and data protection issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 03:34 PM
Security Audit — agent-trust-hub — j5ik2o-takt-optimizer