caveman-evidence-review

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a specialized CLI tool, caveman, to fetch structured data such as cost reports, health scores, and trace summaries. The instructions enforce a strict read-only policy, prohibiting the agent from performing state-changing operations like starting or stopping experiments.
  • [DATA_EXFILTRATION]: The skill accesses cloud-based monitoring and cost data, but the access is scoped to the specific project context. Instructions specifically direct the agent to avoid fetching sensitive request/response payloads by default, focusing instead on metadata and aggregate statistics unless the user explicitly requests otherwise.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:46 PM
Security Audit — agent-trust-hub — caveman-evidence-review