skills/broomva/skills/bstack/Gen Agent Trust Hub

bstack

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references the author's GitHub repository (github.com/broomva/bstack) for downloading the full CLI substrate and companion skill roster.
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone the project repository and execute a bootstrap script (./bin/bstack bootstrap). These are standard installation procedures for the vendor's tooling.
  • [PROMPT_INJECTION]: The skill outlines a governance framework that processes workspace data. Ingestion points: Conversation logs (P1) and workspace state (P15). Boundary markers: Not explicitly mentioned in the primer. Capability inventory: PR management (P4), branch janitoring (P8), and tool authorization policies (P2). Sanitization: No specific content filtering or sanitization of external data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 03:33 PM
Security Audit — agent-trust-hub — bstack