skills/garrytan/gstack/devex-review/Gen Agent Trust Hub

devex-review

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses several local binaries (e.g., gstack-skill-start, gstack-review-log) located in the user's home directory to manage session lifecycle and logging.\n- [DYNAMIC_EXECUTION]: Employs 'eval' to initialize environment variables from tool output and executes JavaScript within automated browser sessions via 'aside repl'.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface for indirect prompt injection as it ingests untrusted web content.\n
  • Ingestion points: Browser snapshots and page text extracted via 'aside' or the fallback headless driver.\n
  • Boundary markers: Headless browser output is wrapped in BEGIN/END UNTRUSTED WEB CONTENT markers.\n
  • Capability inventory: Includes tool access for Bash, Edit, and AskUserQuestion.\n
  • Sanitization: Explicit instructions state that all web content must be treated as untrusted data and not as instructions.\n- [EXTERNAL_DOWNLOADS]: References the Aside browser website (aside.com) as a recommended tool for the audit workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — devex-review