skills/findbene/skills/retro/Gen Agent Trust Hub

retro

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill instructions or preamble logic. The skill follows established patterns for AI agent extensions.
  • [COMMAND_EXECUTION]: The skill executes standard git commands (git log, git fetch, git diff) to analyze repository history. It also invokes several local binaries within the gstack suite (e.g., gstack-config, gstack-slug, gstack-learnings-search) to handle configuration and data processing. These operations are local and aligned with the skill's stated purpose.
  • [DATA_EXFILTRATION]: Includes an opt-in telemetry system that allows the user to share anonymized usage data (skill name, duration, and success status) with the developer. The telemetry is disabled by default, and the prompt explicitly states that no code, file paths, or repo names are sent externally.
  • [PROMPT_INJECTION]: The skill processes untrusted external data, including git commit messages, PR titles, and TODOS.md files, which serves as an ingestion point for indirect prompt injection. However, the risk is minimal as the data is used for generating a structured narrative report, and the agent's behavior is constrained by rigid formatting rules. The capability inventory includes file writes to .context/retros/ and the project's CLAUDE.md, which are handled safely within the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:35 AM
Security Audit — agent-trust-hub — retro