fstack-check

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The agent is instructed to prove that the work functions correctly by running local tests, development servers, or specific commands (e.g., npm test). This activity is confined to the user's local development environment for verification purposes.
  • [PROMPT_INJECTION]: The skill processes untrusted data from the local PLAN.md file and command outputs to conduct its review. While this presents an indirect prompt injection surface, the skill mitigates this risk by explicitly forbidding the agent from applying fixes and requiring it to 'Stop and ask' the user before proceeding. Ingestion points: PLAN.md and terminal output. Boundary markers: Absent. Capability inventory: Local shell command execution. Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 08:59 AM
Security Audit — agent-trust-hub — fstack-check