context-restore
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several vendor-specific binaries from the
~/.claude/skills/gstack/bin/directory (e.g.,gstack-skill-start,gstack-question-log,gstack-learnings-log,gstack-skill-end) to handle operational lifecycle tasks, telemetry, and user interaction logging. These tools are recognized as infrastructure belonging to the skill's author. - [DYNAMIC_EXECUTION]: Employs the
evalcommand to process the output of local scriptsgstack-slugandgstack-paths, enabling dynamic configuration of the shell environment for specific project contexts. - [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves reading and presenting content from external checkpoint files, which constitutes a data ingestion surface.
- Ingestion points: The skill reads markdown files located in
~/.gstack/projects/$SLUG/checkpoints/using shell commands. - Boundary markers: While the skill uses formatted headers to present the restoration data, it does not include explicit instructions for the agent to ignore or sanitize potentially malicious instructions embedded within the checkpoint content.
- Capability inventory: The skill utilizes
Bash,Read,Glob, andGrepto search for and extract data from the filesystem. - Sanitization: There is no evidence of input validation or content filtering applied to the text retrieved from the saved checkpoints.
Audit Metadata