005-agents-installation

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The agent definitions being installed (such as robot-architect and robot-java-coder) include instructions to run local Maven commands.
  • The instructions specify running ./mvnw validate or ./mvnw clean verify to ensure the project's code is valid before performing architecture or coding tasks. These are standard practices for Java development and are triggered as part of the intended developer workflow.
  • [SAFE]: The skill performs documented administrative tasks with explicit user interaction.
  • The installation requires a user-selected destination path (.cursor/agents or .claude/agents).
  • It uses embedded project assets rather than external URLs for its source content.
  • There is no evidence of credential harvesting, network exfiltration, or code obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 04:25 PM
Security Audit — agent-trust-hub — 005-agents-installation