specstory-project-stats
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
nodeto run a local script (scripts/get-stats.js) that performs project identification and network calls.\n- [EXTERNAL_DOWNLOADS]: The skill fetches project statistics fromcloud.specstory.com(or a custom endpoint via environment variable).\n- [DATA_EXPOSURE]: The script reads local configuration files (.specstory/.project.json) and Git metadata (.git/config) to determine the project identifier. While common for development tools, these files contain sensitive repository metadata.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests JSON data from an external API, creating a vulnerability where a compromised API could return malicious strings to influence the agent's behavior.\n - Ingestion points: The response body from
https://cloud.specstory.comis parsed and processed inscripts/get-stats.js.\n - Boundary markers: None; the script outputs data directly to the agent's context without delimiters.\n
- Capability inventory: The skill can read local files and perform network operations.\n
- Sanitization: The API response is parsed as JSON but the resulting string data is not sanitized or validated before being presented to the agent.
Audit Metadata