cso
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple local binaries (e.g.,
gstack-config,gstack-telemetry-log) from the~/.claude/skills/gstack/bin/directory for configuration and telemetry logging.\n- [DATA_EXFILTRATION]: Provides optional, user-consented features for telemetry and artifact synchronization to remote locations, as detailed in interactive prompts.\n- [EXTERNAL_DOWNLOADS]: Includes a version check mechanism that executes a local script to verify if update information is available.\n- [COMMAND_EXECUTION]: Searches git history and environment files for sensitive credential patterns using the Grep tool during its 'Secrets Archaeology' phase.\n- [COMMAND_EXECUTION]: Modifies the project'sCLAUDE.mdfile (with user permission) to add skill routing rules and commits these changes.\n- [SAFE]: The skill includes instructions to ignore adversarial prompts found in audited code, ensuring the integrity of the security audit process.
Audit Metadata