light-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local development tools including git status, git log, and the GitHub CLI (gh run list) to inspect the project environment and CI/CD status for context recovery.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it reads and processes data from external sources such as version control metadata, CI logs, and user-provided conversation transcripts. This risk is addressed through structured 'Confirmation Points' and the integration of automated security and integrity gates that validate data before it influences subsequent pipeline stages.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 05:04 AM
Security Audit — agent-trust-hub — light-orchestrator