design-consultation
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of local, vendor-provided binaries in the
~/.claude/skills/gstack/bin/directory for core operations, including telemetry logging (gstack-skill-end,gstack-question-log), project context recovery (gstack-slug), and browser management (aside,browse). These tools are used within their intended functional scope. - [DYNAMIC_EXECUTION]: The skill uses
evalto execute shell code generated by local binaries (gstack-slugandgstack-paths). This mechanism is employed to dynamically set environment variables and resolve project-specific paths, following a standard pattern for the gstack toolset. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data that could contain malicious instructions, such as web search results, browser snapshots of competitor sites, and project files like
PRODUCT.mdorREADME.md. - Ingestion points: Data enters the agent's context through browser snapshots, web research via the Aside tool, and reading existing project documentation.
- Boundary markers: The instructions explicitly warn the agent that all data returned from web pages and snapshots must be treated strictly as content and never as instructions.
- Capability inventory: The skill possesses capabilities including bash command execution, file system modification, and the ability to spawn subagents (Codex/Claude).
- Sanitization: The skill includes logic to sanitize web queries by removing private information before they are sent to external search providers.
Audit Metadata