ceo
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill has access to the
Bashtool andAgenttool to orchestrate workflows and spawn subagents. These capabilities are aligned with its primary purpose as a CEO/Orchestrator and are governed by strict internal rules, such as requiring user approval before proceeding with project phases. - [DATA_EXPOSURE]: The skill manages internal state, logs, and memory within a specific local directory (
~/.ai-software-agency/). There is no evidence of the skill accessing sensitive system files (e.g., SSH keys, AWS credentials) or exfiltrating data to external domains. - [PROMPT_INJECTION]: No evidence of prompt injection or safety bypass attempts was found. The instructions emphasize strict adherence to governance gates and explicitly forbid the agent from skipping safety-critical steps like feasibility checks.
- [REMOTE_CODE_EXECUTION]: While the skill spawns various subagents (e.g.,
product-manager,fullstack-developer), these are internal components of the multi-agent framework. There are no patterns suggesting the download or execution of untrusted external scripts.
Audit Metadata