ork-explore

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains explicit instructions to remain read-only and avoid modifying files ("Stay read-only", "Do not change files"), which prevents unauthorized modifications to the environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from unfamiliar repositories, which is a known attack surface for indirect prompt injection.
  • Ingestion points: Reads repository files and symbols to map codebase architecture (SKILL.md).
  • Boundary markers: Lacks specific markers like XML tags, but requires the agent to "Cite files and symbols for every material claim" and "distinguish confirmed behavior from inference."
  • Capability inventory: Accesses files via ork_explorer or explorer tools, but is restricted to read-only actions.
  • Sanitization: No specific sanitization or filtering of untrusted data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 06:46 AM
Security Audit — agent-trust-hub — ork-explore