sosa-orchestrator
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate task orchestration and token budget management based on user-defined priorities and historical consumption data.
- [DATA_EXPOSURE]: The skill interacts with local files such as
config/budgets.jsonandaudit/YYYY-MM-DD.jsonlto track session state and budget limits. These files appear to be specific to the SOSA suite of tools and do not contain sensitive system credentials or personal user data. - [INDIRECT_PROMPT_INJECTION]: The skill processes task definitions from
CLAUDE.mdand logs from previous tool executions. While these are external inputs, the orchestrator uses them solely for priority scoring and budget estimation, with no high-risk capabilities (like network access or code evaluation) exposed to potential injection vectors.
Audit Metadata