skills/lvlup-sw/exarchos/plan/Gen Agent Trust Hub

plan

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill contains no malicious code, hidden URLs, or unauthorized data access patterns. It operates strictly within the intended software implementation workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted design requirements from spec files. This risk is minimized by the use of explicit boundary markers (Markdown headers) and automated consistency checks that verify the relationship between requirements and tasks.
  • [COMMAND_EXECUTION]: Workflow management is performed via the 'exarchos' MCP server, which limits the agent to predefined actions like task updating and plan verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 12:27 AM
Security Audit — agent-trust-hub — plan