skills/kevinzai/cc-commander/ao/Gen Agent Trust Hub

ao

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to interact with the 'ao' CLI for spawning agents, checking status, and stopping sessions. It also performs git worktree operations and GitHub CLI commands to facilitate code merging and PR creation.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the '@composio/ao' package from the official NPM registry if the command is not found locally.
  • [PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection.
  • Ingestion points: Processes configuration data from 'agent-orchestrator.yaml' and '.ao/config.yaml', as well as user-provided task descriptions.
  • Boundary markers: None identified.
  • Capability inventory: Executes shell commands for 'ao', 'git', and 'gh' tools.
  • Sanitization: No specific sanitization or validation of the input configuration files or task descriptions is performed before command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 02:29 PM
Security Audit — agent-trust-hub — ao