plan-devex-review
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The preamble and various workflow stages use
evalandsource <(...)to execute the output of local binaries and scripts, such asgstack-slugandgstack-repo-mode. This pattern involves dynamic generation and execution of shell commands based on script output. - [DATA_EXFILTRATION]: The skill implements a telemetry logging mechanism that captures the repository's base name via
git rev-parse --show-toplevel. This behavior contradicts the prompt shown to the user during telemetry opt-in, which claims that no repository names or file paths are collected. - [EXTERNAL_DOWNLOADS]: The 'Artifacts Sync' feature executes
git fetchandgit mergeto synchronize documentation and plans with a remote Git repository, introducing external content into the local environment. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting untrusted data from
WebSearchresults and various local project files (e.g., READMEs, plans, and CHANGELOGs). This external content is used to inform the agent's review logic and is passed to secondary agents or models. - [COMMAND_EXECUTION]: The 'Outside Voice' feature uses the
codex execcommand to run analysis on the current plan, which involves passing potentially untrusted plan content into another execution context.
Audit Metadata