mastra-factory

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a sophisticated security boundary that defaults to read-only operations for status, inspection, and diagnosis tasks. It requires a clearly established operating scope (delegation) before allowing any mutation actions.
  • [SAFE]: Instructions strictly forbid the agent from accessing or revealing sensitive information, including .env files, bearer tokens, and platform credentials. It relies on the CLI's existing authentication state rather than managing secrets itself.
  • [SAFE]: The mutation protocol incorporates high-integrity practices such as optimistic concurrency (using expected revisions), idempotent transitions (using fresh UUID request IDs), and mandatory pre- and post-mutation state verification.
  • [SAFE]: The skill uses standard, well-known tools like jq for structured data parsing and uuidgen for identifier generation, avoiding custom or unverifiable scripts. All CLI commands are directed at the vendor's official operational control plane.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 06:29 AM
Security Audit — agent-trust-hub — mastra-factory