qemu-workflow

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a rigorous process for managing QEMU-related tasks, focusing on auditability and provenance. It includes explicit instructions for redacting credentials and private tokens from all recorded command history, which protects sensitive environment information.
  • [SAFE]: The workflow uses a dedicated local directory structure (.oh-my-qemu/) for all task-related artifacts and leverages Git's exclusion mechanism to prevent sensitive audit data from being accidentally staged or committed to the repository.
  • [SAFE]: Analysis of the workflow steps and referenced documents reveals no suspicious network activity, external dependency downloads from untrusted sources, or hidden executable logic. The skill operates within the local workspace using standard Git and system tools as directed by the user.
  • [SAFE]: The instructions incorporate safety checks regarding project boundaries, specifically directing the agent not to prepare or send generated patches to upstream mailing lists, ensuring that human review remains a prerequisite for external contributions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:32 AM
Security Audit — agent-trust-hub — qemu-workflow