design-html
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several local scripts and binaries (e.g.,
gstack-skill-start,gstack-render.ts,gstack-design-detect.ts,gstack-skill-end) to manage session lifecycle, telemetry, and design rendering. It also uses shell commands for environment detection, context recovery (reading branch information and recent artifacts), and framework identification. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download of a design detector engine binary from the
github.com/pbakaus/impeccablerepository. This action is guarded by a detailedAskUserQuestionprompt that informs the user of the source, licensing, and security implications, requiring explicit human consent before execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources, including
approved.jsonfiles,DESIGN.mdtokens, and CEO plans. The absence of strict boundary markers or sanitization when interpolating this content into the agent's workflow creates a surface for indirect prompt injection, where malicious instructions embedded in project files could influence agent behavior. This is assessed as low risk due to the structured nature of the skill's operations. - [DATA_EXFILTRATION]: The skill logs telemetry data, including session outcomes and errors, to the user's local directory (
~/.gstack/analytics/) using thegstack-skill-endutility. While this data stays on the local system by default, the mechanism exists for tracking skill usage across sessions.
Audit Metadata