nika-authoring

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and instructional text designed to teach an AI agent how to write and validate Nika workflow files (.nika.yaml). It does not contain any executable scripts or hidden logic.
  • [SAFE]: The content explicitly advocates for security best practices, such as least privilege through the 'permits' boundary, secrets management, and using deterministic built-in tools over arbitrary shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes how to handle untrusted data within workflows. It provides a mandatory evidence chain for security by identifying ingestion points, promoting the use of the 'nika check' security oracle for validation, and recommending 'nika:jq' for safe data sanitization to prevent malformed output or command injection in generated workflows.
  • [SAFE]: The external URLs referenced in the documentation (e.g., github.com, rust-lang.org, arxiv.org) are standard technical references and do not represent data exfiltration or malicious download attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 09:20 AM
Security Audit — agent-trust-hub — nika-authoring