gpt-orchestration-auto

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a clear 'authority envelope' that restricts the agent's actions, explicitly prohibiting production data mutation, global software installation, and unauthorized external communications.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an autonomous loop that processes untrusted external data to drive its build and verification actions.
  • Ingestion points: The 'Research' phase in SKILL.md maps repository architecture, SDK usage, and external contracts from files.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the analyzed repository files are provided.
  • Capability inventory: The skill is authorized to perform file writes and execute local repository tools (tests, builds, static checks) during the 'Build' and 'Verify' phases in SKILL.md.
  • Sanitization: There is no evidence of sanitization or validation of external code or documentation content before it influences the orchestration cycles.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 08:51 PM
Security Audit — agent-trust-hub — gpt-orchestration-auto