plan-devex-review

Warn

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The preamble and various workflow stages use eval and source <(...) to execute the output of local binaries and scripts, such as gstack-slug and gstack-repo-mode. This pattern involves dynamic generation and execution of shell commands based on script output.
  • [DATA_EXFILTRATION]: The skill implements a telemetry logging mechanism that captures the repository's base name via git rev-parse --show-toplevel. This behavior contradicts the prompt shown to the user during telemetry opt-in, which claims that no repository names or file paths are collected.
  • [EXTERNAL_DOWNLOADS]: The 'Artifacts Sync' feature executes git fetch and git merge to synchronize documentation and plans with a remote Git repository, introducing external content into the local environment.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting untrusted data from WebSearch results and various local project files (e.g., READMEs, plans, and CHANGELOGs). This external content is used to inform the agent's review logic and is passed to secondary agents or models.
  • [COMMAND_EXECUTION]: The 'Outside Voice' feature uses the codex exec command to run analysis on the current plan, which involves passing potentially untrusted plan content into another execution context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 21, 2026, 06:44 PM
Security Audit — agent-trust-hub — plan-devex-review