fest-methodology

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a set of CLI commands (fest understand, fest create, fest next, fest task, fest commit, fest validate, fest status) to be used by the agent. These commands are typical for project management and version control workflows. The skill instructs the agent to use these tools rather than manual file system manipulation, which encourages structured behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project files (markdown tasks) and directory structures. While these files are external inputs that could theoretically contain instructions, the skill provides a structured methodology and relies on a specific CLI (fest) for processing, which provides a layer of abstraction between the data and the agent's actions. The exposure is considered standard for development-aid skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:04 AM
Security Audit — agent-trust-hub — fest-methodology