skills/simota/agent-skills/nest/Gen Agent Trust Hub

nest

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform directory analysis and restructuring using standard shell utilities such as find, grep, wc, and git mv. These commands are localized to the project environment and are fundamental to the skill's stated purpose of folder optimization.
  • [DATA_EXFILTRATION]: The skill performs read-only analysis of project structures and file metadata (token counts, line lengths) during its AUDIT phase. No network operations, external requests, or attempts to access sensitive system files (e.g., SSH keys, environment variables) were identified.
  • [PROMPT_INJECTION]: The instructions are consistently focused on directory organization and do not contain any patterns intended to bypass agent safety filters, override core instructions, or extract system prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect injection as it ingests and processes data from potentially untrusted project files during its audit and grep-based discovery tests. However, it provides clear boundary markers (such as referencing hierarchical rules in CLAUDE.md) and focuses on structural metadata rather than executing file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 08:28 AM