nika-authoring
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an instructional guide for a specific Domain Specific Language (DSL). It explicitly advocates for a 'default-deny' security posture by requiring authors to define a
permits:block for all filesystem, network, and tool access. - [SAFE]: The document provides clear guidance on managing sensitive information using a dedicated
secrets:authority, discouraging the use of environment variables or hardcoded credentials. - [SAFE]: Although the skill describes advanced features like the
lift:block (which can bypass certain static checks for 'taint' or 'data-as-code'), these are documented as sanctioned, reviewable features requiring human-readable justifications rather than covert exploitation techniques. - [SAFE]: External domain references (e.g., github.com, rust-lang.org) are used strictly as examples for teaching users how to configure network access boundaries.
- [SAFE]: The skill includes instructions to use automated checking tools (
nika check) to identify and repair security vulnerabilities (such as NIKA-SEC-004) before workflows are executed, which acts as a built-in safety guardrail.
Audit Metadata