design-consultation

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of local, vendor-provided binaries in the ~/.claude/skills/gstack/bin/ directory for core operations, including telemetry logging (gstack-skill-end, gstack-question-log), project context recovery (gstack-slug), and browser management (aside, browse). These tools are used within their intended functional scope.
  • [DYNAMIC_EXECUTION]: The skill uses eval to execute shell code generated by local binaries (gstack-slug and gstack-paths). This mechanism is employed to dynamically set environment variables and resolve project-specific paths, following a standard pattern for the gstack toolset.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data that could contain malicious instructions, such as web search results, browser snapshots of competitor sites, and project files like PRODUCT.md or README.md.
  • Ingestion points: Data enters the agent's context through browser snapshots, web research via the Aside tool, and reading existing project documentation.
  • Boundary markers: The instructions explicitly warn the agent that all data returned from web pages and snapshots must be treated strictly as content and never as instructions.
  • Capability inventory: The skill possesses capabilities including bash command execution, file system modification, and the ability to spawn subagents (Codex/Claude).
  • Sanitization: The skill includes logic to sanitize web queries by removing private information before they are sent to external search providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — design-consultation