paw-pa-agent-orchestrator

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured workflow management system that uses a local workspace directory (.pawbytes/) to store and retrieve proposal artifacts. This encapsulated file access is consistent with its stated purpose as a project orchestrator.
  • [PROMPT_INJECTION]: As a coordinator that processes multimodal briefs and research data, the skill possesses an indirect prompt injection surface. It mitigates this risk through 'Guided Mode,' which requires explicit human approval at key pipeline stages (Research, Pricing, Draft) before proceeding, and 'Autonomous Mode,' which mandates that all assumptions made during processing are prominently flagged for user review.
  • [CREDENTIALS_UNSAFE]: References to sensitive data like API keys (e.g., assemblyai_api_key) are correctly handled as configuration parameters to be loaded from the project root rather than being hardcoded within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 03:55 AM
Security Audit — agent-trust-hub — paw-pa-agent-orchestrator