ceo

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill has access to the Bash tool and Agent tool to orchestrate workflows and spawn subagents. These capabilities are aligned with its primary purpose as a CEO/Orchestrator and are governed by strict internal rules, such as requiring user approval before proceeding with project phases.
  • [DATA_EXPOSURE]: The skill manages internal state, logs, and memory within a specific local directory (~/.ai-software-agency/). There is no evidence of the skill accessing sensitive system files (e.g., SSH keys, AWS credentials) or exfiltrating data to external domains.
  • [PROMPT_INJECTION]: No evidence of prompt injection or safety bypass attempts was found. The instructions emphasize strict adherence to governance gates and explicitly forbid the agent from skipping safety-critical steps like feasibility checks.
  • [REMOTE_CODE_EXECUTION]: While the skill spawns various subagents (e.g., product-manager, fullstack-developer), these are internal components of the multi-agent framework. There are no patterns suggesting the download or execution of untrusted external scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:49 PM
Security Audit — agent-trust-hub — ceo