dacp-assembler

Pass

Audited by Gen Agent Trust Hub on Mar 9, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides instructions for assembling agent communication bundles and contains no attempts to override safety protocols or ignore system instructions.\n- [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or network requests was found within the skill files.\n- [REMOTE_CODE_EXECUTION]: Although the skill handles executable scripts for bundles, it selects them from an existing catalog and explicitly prohibits runtime code generation. No remote code downloading is present.\n- [COMMAND_EXECUTION]: The skill uses standard file manipulation tools (Read, Grep, Glob, Bash) for its assembly tasks. No dangerous command patterns or privilege escalation attempts were detected.\n- [SAFE]: The skill incorporates several security design principles, including size limits for payloads, mandatory provenance for scripts, and the SAFE-02 protocol which limits fidelity level changes to prevent rapid adaptation risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 9, 2026, 08:35 PM
Security Audit — agent-trust-hub — dacp-assembler