skills/garrytan/gstack/design-review/Gen Agent Trust Hub

design-review

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill offers a one-time setup to download the 'impeccable' design detector engine from a public GitHub repository. While the download is initiated via a user-facing consent prompt (AskUserQuestion) and uses checksum verification, it introduces a third-party binary into the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and acting upon untrusted data from multiple sources. This represents a significant attack surface where malicious instructions could be embedded in processed content to influence the agent's code-modification behavior.
  • Ingestion points: Project configuration and documentation files (DESIGN.md, CLAUDE.md, TESTING.md), rendered DOM dumps from analyzed web pages, and results from WebSearch and aside exec tools.
  • Boundary markers: The headless browser wrapper ($B) uses ═══ BEGIN/END UNTRUSTED WEB CONTENT ═══ markers to delimit untrusted output. However, other ingestion points like file reads lack explicit boundary protection in the provided instructions.
  • Capability inventory: The skill has broad capabilities including filesystem modification (Write, Edit), shell access (Bash), and version control (git commit), which can be leveraged if an injection succeeds.
  • Sanitization: The skill utilizes a gstack-redact tool to remove PII from DOM dumps before scanning, but it does not specify content-filtering mechanisms to prevent instruction injection from those files.
  • [COMMAND_EXECUTION]: Extensive use of shell commands is documented for environment setup, context recovery (using find, grep, sed), and project management. These commands operate within the vendor's local state directories (~/.gstack/).
  • [DYNAMIC_EXECUTION]: The skill utilizes aside repl to execute JavaScript within a browser context and codex exec to perform remote code analysis. These tools are used for legitimate audit tasks but involve the dynamic execution of generated logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 07:43 AM
Security Audit — agent-trust-hub — design-review