fest-execution

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the fest and fgo CLI utilities for state mutation and project linking. \n- [INDIRECT_PROMPT_INJECTION]: The skill processes task documents containing YAML frontmatter hooks (pre, post, start), creating a surface for indirect instructions to influence agent behavior. \n
  • Ingestion points: Task document frontmatter in SKILL.md. \n
  • Boundary markers: None identified. \n
  • Capability inventory: fest command execution. \n
  • Sanitization: None identified. \n- [DYNAMIC_EXECUTION]: The skill uses eval for shell initialization (eval "$(fest shell-init zsh)"), which executes dynamically generated shell code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:04 AM
Security Audit — agent-trust-hub — fest-execution