skills/google/mantis/mantis-plan/Gen Agent Trust Hub

mantis-plan

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • Dynamic Script Generation: In Mode A, the skill instructs the agent to programmatically generate and execute scripts to crawl directories and identify production files. While this is an efficient way to handle large repositories, it involves the generation of executable content on the host.
  • External Tool Integration: The instructions encourage the use of specialized security utilities like Ghidra, radare2, and angr. These are standard industry tools for artifact analysis that operate within the command-line environment.
  • Workspace Data Ingestion: The agent reads from workspace files like THREAT_MODEL.md and index.md to inform its planning. As this data influences the audit roadmap, users should ensure that these knowledge base files are from a trusted origin.
  • Adversarial Audit Logic: The skill can generate tasks that instruct the researcher to ignore defined trust boundaries for exploratory testing. This is a common practice in security auditing but highlights the importance of executing such reviews in isolated environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:21 PM
Security Audit — agent-trust-hub — mantis-plan