os-architect

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates as an SME-facing architect for evolving local agent ecosystems, with no evidence of malicious intent or unauthorized access.
  • [COMMAND_EXECUTION]: Employs Bash and Write tools to perform legitimate development operations, including scaffolding via create-sub-agent and planning via os-evolution-planner.
  • [EXTERNAL_DOWNLOADS]: References official tools like the GitHub CLI (gh) and Copilot CLI for dispatching tasks. These are well-known services and do not involve untrusted remote downloads.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes untrusted user descriptions to generate and execute code. Ingestion points: User-provided descriptions in Phase 1 (SKILL.md). Boundary markers: No explicit delimiters detected in processing logic. Capability inventory: Access to Bash, Write, and sub-agent dispatching. Sanitization: No validation of user input is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:07 PM
Security Audit — agent-trust-hub — os-architect