skills/garrytan/gstack/careful/Gen Agent Trust Hub

careful

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a PreToolUse hook that executes a local bash script (check-careful.sh) to inspect terminal commands for destructive patterns before they are allowed to proceed.
  • [COMMAND_EXECUTION]: The safety check script utilizes locally available python3 or node interpreters to perform safe JSON parsing and processing of tool inputs.
  • [SAFE]: The skill records usage statistics, including a timestamp, skill name, and the current repository's folder name, into a local file at ~/.gstack/analytics/skill-usage.jsonl. This telemetry is restricted to the local filesystem and does not involve network exfiltration.
  • [SAFE]: The skill includes robust logic to detect and warn against shell obfuscation techniques like IFS word-splitting and base64-to-shell pipes in the commands it monitors.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — careful