cso
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes several local scripts located in
~/.claude/skills/gstack/bin/(includinggstack-config,gstack-team-init, andgstack-learnings-log) to manage tool settings, facilitate migration from vendored versions, and log architectural insights discovered during audits. - [DYNAMIC_EXECUTION]: Uses the
evalcommand to execute the output of the local script~/.claude/skills/gstack/bin/gstack-slug. This is a common pattern for dynamically setting environment variables based on script output. - [PROMPT_INJECTION]: As an auditor of untrusted code, the skill is inherently exposed to indirect prompt injection. It includes a proactive mitigation instruction ("Anti-manipulation") that explicitly directs the agent to ignore any instructions found within the analyzed codebase that attempt to influence the audit methodology or findings.
Audit Metadata