github-orchestration

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional documentation in markdown format. No executable scripts (.sh, .py, .js) or binary files are included in the skill package.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network exfiltration patterns were detected. The skill does not perform any network operations (e.g., curl, wget, fetch).
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: There are no package manifest files (e.g., package.json, requirements.txt) and no commands that download or execute remote code.
  • [PROMPT_INJECTION]: The instructions provide procedural guidance for agents without attempting to override system safety filters or bypass core agent constraints. The language used ("Merge gates are absolute", "Never claim a phase you skipped") is consistent with established coordination best practices.
  • [OBFUSCATION]: A manual and automated review of the content found no evidence of hidden URLs, Base64-encoded commands, zero-width characters, or homoglyph-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:14 AM
Security Audit — agent-trust-hub — github-orchestration