kiro-discovery
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs directory listings and metadata scans of project-specific files (e.g.,
.kiro/specs/,.kiro/steering/) to determine the project state. These operations are limited in scope and do not involve sensitive system paths. - [SAFE]: The skill uses sub-agents for codebase exploration and research, which is a common pattern for managing context budget in AI agent environments. It explicitly limits findings to under 200 lines to prevent context overflow.
- [SAFE]: The file writing operations are restricted to the project's own
.kiroconfiguration directory for persistence of discovery results. This is standard behavior for a project management skill. - [SAFE]: No network exfiltration, hardcoded credentials, or obfuscation techniques were detected in the instructions or configuration files.
Audit Metadata