build-agent

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements safety measures by requiring explicit user confirmation via the AskUserQuestion tool before performing destructive actions such as deleting or overwriting agents and knowledge bases.- [COMMAND_EXECUTION]: The skill uses Bash and file manipulation tools (Read, Write, Edit) to manage local agent configuration files. These actions are directly aligned with the skill's purpose as an agent architect tool.- [EXTERNAL_DOWNLOADS]: The skill communicates with official vendor infrastructure at api.orq.ai and docs.orq.ai for agent creation and documentation lookup. These are necessary and legitimate service interactions.- [DATA_EXPOSURE]: Guidance for API interactions correctly identifies the use of environment variables (e.g., $ORQ_API_KEY) for secret management, avoiding hardcoded credentials. It also provides instructions for scoped memory management to prevent data leakage between users.- [SAFE]: Ingestion of untrusted data via Knowledge Bases is managed through structured retrieval processes. The provided system instruction templates include boundary markers and explicit constraints to mitigate risks of unintended instruction following.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 11:21 AM