skills/simota/agent-skills/orbit/Gen Agent Trust Hub

orbit

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates and executes shell scripts (run-loop.sh, bootstrap.sh, verify.sh) that perform arbitrary command execution. It primarily drives AI executors like codex, claude, and agy (Antigravity) using flags like --dangerously-skip-permissions or --full-auto, which allow autonomous tool usage without human confirmation.
  • [DYNAMIC_EXECUTION]: The skill's core functionality involves runtime generation of executable bash scripts from templates. It uses bash -c to execute user-defined or template-derived EXEC_CMD strings, and utilizes a Perl-based wrapper (portable_timeout) to manage execution lifecycles and timeouts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from goal.md and progress.md (which may be influenced by external sources or the agent's own prior output) to drive execution loops. This surface is mitigated by requirements for measurable acceptance criteria (AC), independent verification commands, and a separate CRITIC_MODEL to gate the completion of tasks.
  • [EXTERNAL_DOWNLOADS]: The generated notify.sh script suggests the use of the edge-tts package for audio notifications. Additionally, the skill's auditing and verification templates reference several external developer tools and linters (e.g., jscpd, ts-prune, depcheck, playwright).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — orbit