dotnet-testing-orchestrator-aspire

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local Node.js script located at .claude/scripts/token-usage/token_usage.js via the Bash tool to perform token usage tracking and reporting. This is a standard utility function within the project environment.
  • [PROMPT_INJECTION]: The skill includes 'HARD STOP' instructions that act as operational guardrails. These prevent the orchestrator from directly modifying source code or bypassing subagent phases, ensuring the agent adheres to the prescribed workflow architecture.
  • [REMOTE_CODE_EXECUTION]: The orchestrator is designed to delegate test execution to a subagent (dotnet-testing-advanced-aspire-executor). The instructions facilitate the use of standard development tools like dotnet test and dotnet build as part of its primary functional purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:31 PM
Security Audit — agent-trust-hub — dotnet-testing-orchestrator-aspire