invoke-task-conventions

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists of Markdown documentation and best practice guidelines for task organization. No executable code or scripts are included in the skill files.
  • [COMMAND_EXECUTION]: The documentation contains illustrative examples of CLI commands (e.g., inv, docker, kubectl) and code snippets (c.run, subprocess). These are for educational purposes and do not execute unauthorized commands.
  • [CREDENTIALS_UNSAFE]: The content identifies a specific behavior in the pyinvoke library where interactive sudo prompts can echo passwords in cleartext. It recommends security best practices, such as using sudo -n and DEBIAN_FRONTEND=noninteractive.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface where certain task names are auto-approved by the agent platform and provides explicit guidelines to ensure those tasks are non-mutating, thereby mitigating the risk of unauthorized system changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:53 AM
Security Audit — agent-trust-hub — invoke-task-conventions