nestr-insights

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the nestr command-line interface to perform workspace operations such as managing links (nestr links) and retrieving metrics (nestr insights). This is the primary function of the skill and uses the vendor's specialized tool.
  • [EXTERNAL_DOWNLOADS]: References official documentation and command configuration hosted on the vendor's official GitHub repository at github.com/nestr-dev/nestr-cli. This is used for setup and environment reference.
  • [DATA_EXPOSURE]: Includes functionality to export comprehensive workspace governance and work trees into local JSON files (work.json and governance.json). These files are stored locally on the user's system.
  • [PROMPT_INJECTION]: As the skill ingests and processes workspace data (metrics, link relations, and tree exports), there is a potential surface for indirect prompt injection if the resulting data is later processed by an agent without sanitization. Ingestion points: nestr insights and nestr export commands; Capabilities: local file writing; Boundary markers: not explicitly defined in the provided instructions; Sanitization: not mentioned in the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 03:05 PM
Security Audit — agent-trust-hub — nestr-insights