gstack-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches updates and clones the tool's source code from the official vendor repository on GitHub.
- [REMOTE_CODE_EXECUTION]: Automatically executes the setup script provided in the downloaded package and runs local migration scripts to update the installation.
- [COMMAND_EXECUTION]: Uses shell commands to detect installation paths, manage backups, synchronize local copies, and manage background processes via localhost network checks.
- [DYNAMIC_EXECUTION]: Dynamically identifies and executes version-specific migration scripts stored within the skill's package to update configurations and fix legacy directory structures.
- [INDIRECT_PROMPT_INJECTION]: The skill processes the CHANGELOG.md file from the updated repository to display new features to the user, which is a potential surface for indirect prompt injection, though mitigated by the trusted nature of the source repository.
Audit Metadata