invoke-task-conventions
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists of Markdown documentation and best practice guidelines for task organization. No executable code or scripts are included in the skill files.
- [COMMAND_EXECUTION]: The documentation contains illustrative examples of CLI commands (e.g.,
inv,docker,kubectl) and code snippets (c.run,subprocess). These are for educational purposes and do not execute unauthorized commands. - [CREDENTIALS_UNSAFE]: The content identifies a specific behavior in the
pyinvokelibrary where interactivesudoprompts can echo passwords in cleartext. It recommends security best practices, such as usingsudo -nandDEBIAN_FRONTEND=noninteractive. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface where certain task names are auto-approved by the agent platform and provides explicit guidelines to ensure those tasks are non-mutating, thereby mitigating the risk of unauthorized system changes.
Audit Metadata