skills/garrytan/gstack/gstack-upgrade/Gen Agent Trust Hub

gstack-upgrade

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the latest version of the gstack toolset from the author's GitHub repository (github.com/garrytan/gstack.git) when updating vendored installations.\n- [COMMAND_EXECUTION]: Executes ./setup and various migration scripts (e.g., in the migrations/ directory) to finalize updates and maintain configuration consistency. These scripts perform tasks such as file cleanup and state migration using standard shell utilities.\n- [PROMPT_INJECTION]: The skill processes and summarizes CHANGELOG.md from the newly updated version to inform the user of new features, representing a standard indirect prompt injection surface for data ingested from the package itself.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 09:44 PM