devex-review
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses several local binaries (e.g., gstack-skill-start, gstack-review-log) located in the user's home directory to manage session lifecycle and logging.\n- [DYNAMIC_EXECUTION]: Employs 'eval' to initialize environment variables from tool output and executes JavaScript within automated browser sessions via 'aside repl'.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface for indirect prompt injection as it ingests untrusted web content.\n
- Ingestion points: Browser snapshots and page text extracted via 'aside' or the fallback headless driver.\n
- Boundary markers: Headless browser output is wrapped in BEGIN/END UNTRUSTED WEB CONTENT markers.\n
- Capability inventory: Includes tool access for Bash, Edit, and AskUserQuestion.\n
- Sanitization: Explicit instructions state that all web content must be treated as untrusted data and not as instructions.\n- [EXTERNAL_DOWNLOADS]: References the Aside browser website (aside.com) as a recommended tool for the audit workflow.
Audit Metadata