uni-agent

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Static detection identified standard implementation of subprocess.Popen in scripts/test_all.py used strictly to launch temporary local mock testing servers (a2a_server.py, aitp_server.py, etc.). This usage is entirely safe and appropriate for internal test management and workflow orchestration.
  • [EXTERNAL_DOWNLOADS]: The skill interfaces with standard infrastructure URLs and known protocols (such as open-source agent ecosystems). No untrusted or malicious remote execution components were discovered.
  • [CREDENTIALS_UNSAFE]: The project follows standard development best practices by defining credential placeholders (e.g., ${A2A_API_KEY}, ${GITHUB_TOKEN}) inside config/agents.yaml instead of hardcoding live authentication values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:23 AM
Security Audit — agent-trust-hub — uni-agent