governance

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script scripts/validate_tokens.py. This is a routine validation step within the governance workflow and does not involve remote code or elevated privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential attack surface by ingesting data from project-local files. 1. Ingestion points: workflows/governance.md, CLAUDE.md, and design-systems/crosswalk.md. 2. Boundary markers: No specific delimiters or safety instructions are defined for processing this content. 3. Capability inventory: The agent can execute shell commands via Python. 4. Sanitization: No sanitization or validation of the markdown content is specified before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 05:32 PM
Security Audit — agent-trust-hub — governance