skills/yonatangross/orchestkit/dream/Gen Agent Trust Hub

dream

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to perform file operations and execute claude CLI commands for plugin and project management.
  • [DYNAMIC_EXECUTION]: The skill executes a local Node.js script (scripts/index-budget.mjs) to perform deterministic calculations for memory index management.
  • [DATA_EXFILTRATION]: The skill reads sensitive internal agent data, including logs, configuration files, and memory files across all projects. This data is used locally for consolidation logic and is not sent over the network.
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates the content of memory files to determine pruning eligibility. Maliciously crafted memory entries could potentially use specific keywords (e.g., 'never', 'avoid') to influence the pruning logic and prevent their own deletion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:15 AM
Security Audit — agent-trust-hub — dream