gstack-upgrade
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the latest version of the gstack toolset from the author's GitHub repository (
github.com/garrytan/gstack.git) when updating vendored installations.\n- [COMMAND_EXECUTION]: Executes./setupand various migration scripts (e.g., in themigrations/directory) to finalize updates and maintain configuration consistency. These scripts perform tasks such as file cleanup and state migration using standard shell utilities.\n- [PROMPT_INJECTION]: The skill processes and summarizesCHANGELOG.mdfrom the newly updated version to inform the user of new features, representing a standard indirect prompt injection surface for data ingested from the package itself.
Audit Metadata