estimate-actual
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses standard utilities like
gitandgh(GitHub CLI) to retrieve diffs, logs, and pull request information for estimation analysis.\n- [COMMAND_EXECUTION]: Executes a local script.claude/scripts/code_graphto perform dependency tracing and calculate the blast radius of changes.\n- [DATA_EXPOSURE]: Accesses local project documentation and configuration files to identify relevant patterns and settings.\n- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data including git diffs and project plans.\n - Ingestion points: Reads
git diff,git log,gh pr view, and plan markdown files.\n - Boundary markers: The skill instructions do not define explicit delimiters for ingested external content.\n
- Capability inventory: Includes shell execution for git/gh tools and file-write access to
plans/_estimation-samples.csv.\n - Sanitization: No explicit sanitization or filtering of ingested data is mentioned in the protocol.
Audit Metadata