heist
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to use standard file system operations including glob, grep, read, and write to analyze the repository structure and save implementation plans in the docs/plans/ folder.
- [PROMPT_INJECTION]: The skill processes project specifications and ADRs, which introduces a potential surface for indirect prompt injection. (1) Ingestion points: External PRD documents, architectural records in docs/adr/, and user briefs. (2) Boundary markers: None present. (3) Capability inventory: File system read and write access. (4) Sanitization: Not specified in the instructions.
Audit Metadata