skills/lvlup-sw/exarchos/delegate/Gen Agent Trust Hub

delegate

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard development tool for multi-agent coordination. It prioritizes worktree isolation and automated verification (TDD, static analysis) as core principles, which are positive security practices for autonomous agents.
  • [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection because it ingests implementation plans and review reports to generate instructions for subagents. However, the use of structured prompt templates and mandatory quality gates (tests and linting) provides significant mitigation against adversarial data. This risk is inherent to the skill's primary function of delegation.
  • [COMMAND_EXECUTION]: The skill uses git commands for managing worktrees and branches, and it references project toolchain commands like npm install and npm run sync:schemas. All identified commands are executed within the local project context as part of typical developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 12:27 AM
Security Audit — agent-trust-hub — delegate