context-restore

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several vendor-specific binaries from the ~/.claude/skills/gstack/bin/ directory (e.g., gstack-skill-start, gstack-question-log, gstack-learnings-log, gstack-skill-end) to handle operational lifecycle tasks, telemetry, and user interaction logging. These tools are recognized as infrastructure belonging to the skill's author.
  • [DYNAMIC_EXECUTION]: Employs the eval command to process the output of local scripts gstack-slug and gstack-paths, enabling dynamic configuration of the shell environment for specific project contexts.
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves reading and presenting content from external checkpoint files, which constitutes a data ingestion surface.
  • Ingestion points: The skill reads markdown files located in ~/.gstack/projects/$SLUG/checkpoints/ using shell commands.
  • Boundary markers: While the skill uses formatted headers to present the restoration data, it does not include explicit instructions for the agent to ignore or sanitize potentially malicious instructions embedded within the checkpoint content.
  • Capability inventory: The skill utilizes Bash, Read, Glob, and Grep to search for and extract data from the filesystem.
  • Sanitization: There is no evidence of input validation or content filtering applied to the text retrieved from the saved checkpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — context-restore