agentic-os

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a documentation and template resource for structuring AI projects. It does not contain malicious code, obfuscation, or unauthorized remote execution patterns.
  • [PROMPT_INJECTION]: The architecture utilizes local files in a data/ directory as a persistent memory layer. This creates a surface for indirect prompt injection where the agent might process instructions embedded in stored data (e.g., logs, project context, or inbox files). The skill assumes these files are managed within a trusted local environment.
  • [CREDENTIALS_UNSAFE]: The skill includes explicit security guidance in its 'Anti-Patterns' section, warning users against hardcoding API keys in agent files and recommending the use of environment variables as a safe alternative.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 04:59 AM