mantis-plan
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- Dynamic Script Generation: In Mode A, the skill instructs the agent to programmatically generate and execute scripts to crawl directories and identify production files. While this is an efficient way to handle large repositories, it involves the generation of executable content on the host.
- External Tool Integration: The instructions encourage the use of specialized security utilities like Ghidra, radare2, and angr. These are standard industry tools for artifact analysis that operate within the command-line environment.
- Workspace Data Ingestion: The agent reads from workspace files like THREAT_MODEL.md and index.md to inform its planning. As this data influences the audit roadmap, users should ensure that these knowledge base files are from a trusted origin.
- Adversarial Audit Logic: The skill can generate tasks that instruct the researcher to ignore defined trust boundaries for exploratory testing. This is a common practice in security auditing but highlights the importance of executing such reviews in isolated environments.
Audit Metadata