skills/garrytan/gstack/canary/Gen Agent Trust Hub

canary

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local utility binaries located in the ~/.claude/skills/gstack/bin/ directory to manage session state, recover project context, and log telemetry after execution.
  • [DYNAMIC_EXECUTION]: The skill utilizes eval to source environment variables from a local script and executes JavaScript templates within a browser context (Aside or a headless fallback) to collect page navigation and console data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external websites, creating a surface for indirect prompt injection. Ingestion points: External URLs provided by the user and visited during baseline and monitoring phases. Boundary markers: Explicit instructions in the skill body to treat all browser-returned content as data only, along with tool-enforced delimiters for untrusted content. Capability inventory: Local command execution for logging, file writing for report generation, and network navigation via the browser driver. Sanitization: Extraction of metrics via JSON stringification and instructional guardrails that forbid treating page content as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:02 AM
Security Audit — agent-trust-hub — canary