ai-coding-agents-tasks

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references documentation, implementation guides, and tutorials from well-known services and trusted organizations, including Anthropic (code.claude.com, github.com/anthropics) and OpenAI (github.com/openai). These are used exclusively for architectural reference and best-practice guidance.
  • [COMMAND_EXECUTION]: The skill includes a Python validator script (scripts/recipe_scanner.py) which uses standard libraries to perform static analysis on YAML task blueprints. The script includes proactive security features that identify and flag high-risk capabilities such as network access, filesystem writes, and shell execution within recipes.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for processing external recipe files. This ingestion surface is mitigated by the inclusion of a static validation script designed to audit these files for high-risk extension usage before they are loaded into the agent's runtime context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:06 PM
Security Audit — agent-trust-hub — ai-coding-agents-tasks