qemu-flow-plan

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces a strict 'Artifact root rule', mandating that all agent-created files (plans, logs, scripts, and reports) must reside within a specific sub-directory: build/agent/<task-slug>/. This prevents the agent from polluting the main source tree or writing to sensitive system paths.
  • [SAFE]: It includes a 'Hard policy boundary' that explicitly forbids the agent from adding contribution trailers like Signed-off-by or Reviewed-by. This is a safety measure to ensure compliance with QEMU's upstream policies regarding AI-generated content.
  • [SAFE]: The instructions focus on documentation, planning, and local research. While it mentions build and boot commands in the context of QEMU development, it does not include arbitrary command execution, network exfiltration, or credential access.
  • [SAFE]: No obfuscation, remote code execution patterns, or suspicious dependencies were identified in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 06:22 AM
Security Audit — agent-trust-hub — qemu-flow-plan