document-release

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash tool to execute git operations (git diff, git log, git merge-base, git commit, git push), platform CLI commands (gh for GitHub, glab for GitLab), and various local utility binaries provided by the gstack ecosystem (e.g., gstack-skill-start, gstack-slug, gstack-decision-log). These are standard operational requirements for a repository management skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository's documentation files (find . -name "*.md") and the existing PR/MR body (gh pr view / glab mr view).
  • Ingestion points: Document files and platform PR descriptions (Step 1, Step 9).
  • Boundary markers: The skill uses gstack-issue-guard --stdin --source pr-body to wrap ingested PR content in a trust envelope.
  • Capability inventory: Includes file writing, git commits, and network operations via platform CLIs.
  • Sanitization: Employs gstack-redact to scan and redact sensitive information before updating external PR bodies. Instructions explicitly warn the agent to ignore any directions contained within the ingested data.
  • [DYNAMIC_EXECUTION]: The skill uses eval to process the output of the local gstack-slug utility. It also instructs the agent to follow GSTACK_INSTRUCTION blocks that may be dynamically generated by the gstack-skill-start tool. These patterns are used for environment configuration and onboarding in the gstack framework.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions the use of Codex (an OpenAI service) and provides instructions for the user to install the @openai/codex package via npm if it is missing. This is a legitimate dependency for the optional cross-model documentation review feature.
  • [DATA_EXFILTRATION]: The skill sends execution telemetry (session ID, outcome, error messages) via the gstack-skill-end tool and updates PR/MR descriptions on external hosting platforms. These operations are transparently documented as part of the skill's primary functionality for project documentation management.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — document-release