specstory-project-stats

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses node to run a local script (scripts/get-stats.js) that performs project identification and network calls.\n- [EXTERNAL_DOWNLOADS]: The skill fetches project statistics from cloud.specstory.com (or a custom endpoint via environment variable).\n- [DATA_EXPOSURE]: The script reads local configuration files (.specstory/.project.json) and Git metadata (.git/config) to determine the project identifier. While common for development tools, these files contain sensitive repository metadata.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests JSON data from an external API, creating a vulnerability where a compromised API could return malicious strings to influence the agent's behavior.\n
  • Ingestion points: The response body from https://cloud.specstory.com is parsed and processed in scripts/get-stats.js.\n
  • Boundary markers: None; the script outputs data directly to the agent's context without delimiters.\n
  • Capability inventory: The skill can read local files and perform network operations.\n
  • Sanitization: The API response is parsed as JSON but the resulting string data is not sanitized or validated before being presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — specstory-project-stats