skills/garrytan/gstack/diagram/Gen Agent Trust Hub

diagram

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various utility binaries from the ~/.claude/skills/gstack/bin/ directory to handle session state, telemetry, and project-specific settings.
  • [COMMAND_EXECUTION]: Utilizes eval and source on the output of local scripts (gstack-slug, gstack-repo-mode) to dynamically configure the environment.
  • [COMMAND_EXECUTION]: Interacts with a local browser daemon to process Mermaid source code into SVG, PNG, and Excalidraw formats using a local HTML bundle.
  • [EXTERNAL_DOWNLOADS]: Includes logic to check for software updates and send usage telemetry to the author's infrastructure, contingent on user approval.
  • [EXTERNAL_DOWNLOADS]: References external documentation at https://garryslist.org/posts/boil-the-ocean to provide context for its 'Boil the Ocean' design principle.
  • [COMMAND_EXECUTION]: Offers to modify the local project's CLAUDE.md file to insert skill routing rules, which helps the agent identify when to invoke specific tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 10:43 AM
Security Audit — agent-trust-hub — diagram