exploring
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
grepin Phase 2 to perform a quick scan of the local codebase (specificallysrc/andapp/directories) to identify relevant files and existing patterns. This operation is restricted to searching and does not execute found content. - [DATA_EXFILTRATION]: The skill reads project-specific configuration files such as
.khuym/onboarding.jsonand.khuym/STATE.mdto maintain internal workflow state. It does not perform any network operations to external or untrusted domains. - [PROMPT_INJECTION]: Phase 4.2 involves spawning a subagent with a specific prompt to review the generated
CONTEXT.md. While the content being reviewed is derived from user input and codebase scans, the subagent's instructions are focused on document completeness and clarity, minimizing the risk of instruction override. - [EXTERNAL_DOWNLOADS]: The skill provides a link to the
gsd-build/get-shit-donerepository on GitHub as a reference for its methodology. This is a legitimate reference to a well-known open-source project.
Audit Metadata