light-orchestrator
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local development tools including
git status,git log, and the GitHub CLI (gh run list) to inspect the project environment and CI/CD status for context recovery. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it reads and processes data from external sources such as version control metadata, CI logs, and user-provided conversation transcripts. This risk is addressed through structured 'Confirmation Points' and the integration of automated security and integrity gates that validate data before it influences subsequent pipeline stages.
Audit Metadata