workbench-flue-agent-harness
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and configuration from external sources including
flueframework.comand the official GitHub repository of thewithastroorganization. These are well-known or official sources for the framework described. - [CREDENTIALS_UNSAFE]: The skill includes explicit safety rules prohibiting the generation or storage of secrets, API keys, or tokens in documentation or code. It recommends an
env-onlysecrets policy for agents requiring credentials, which aligns with industry best practices. - [COMMAND_EXECUTION]: The skill mentions the use of
flueCLI tools (e.g.,flue dev,flue init) for local development and scaffolding. These operations are within the stated purpose of the skill for agent management and deployment.
Audit Metadata