document-release
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bashtool to execute git operations (git diff,git log,git merge-base,git commit,git push), platform CLI commands (ghfor GitHub,glabfor GitLab), and various local utility binaries provided by the gstack ecosystem (e.g.,gstack-skill-start,gstack-slug,gstack-decision-log). These are standard operational requirements for a repository management skill. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's documentation files (
find . -name "*.md") and the existing PR/MR body (gh pr view/glab mr view). - Ingestion points: Document files and platform PR descriptions (Step 1, Step 9).
- Boundary markers: The skill uses
gstack-issue-guard --stdin --source pr-bodyto wrap ingested PR content in a trust envelope. - Capability inventory: Includes file writing, git commits, and network operations via platform CLIs.
- Sanitization: Employs
gstack-redactto scan and redact sensitive information before updating external PR bodies. Instructions explicitly warn the agent to ignore any directions contained within the ingested data. - [DYNAMIC_EXECUTION]: The skill uses
evalto process the output of the localgstack-slugutility. It also instructs the agent to followGSTACK_INSTRUCTIONblocks that may be dynamically generated by thegstack-skill-starttool. These patterns are used for environment configuration and onboarding in the gstack framework. - [EXTERNAL_DOWNLOADS]: The documentation mentions the use of Codex (an OpenAI service) and provides instructions for the user to install the
@openai/codexpackage via npm if it is missing. This is a legitimate dependency for the optional cross-model documentation review feature. - [DATA_EXFILTRATION]: The skill sends execution telemetry (session ID, outcome, error messages) via the
gstack-skill-endtool and updates PR/MR descriptions on external hosting platforms. These operations are transparently documented as part of the skill's primary functionality for project documentation management.
Audit Metadata