skills/garrytan/gstack/health/Gen Agent Trust Hub

health

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local binaries for lifecycle management and project-specific development tools to gather metrics.\n
  • Evidence:\n
  • Execution of vendor binaries: gstack-skill-start, gstack-slug, gstack-learnings-log, and gstack-skill-end.\n
  • Execution of project tools: tsc, biome, eslint, ruff, pytest, cargo test, go test, knip, shellcheck, and gbrain.\n- [INDIRECT_PROMPT_INJECTION]: The skill parses and displays output from external development tools, which represents an attack surface for indirect prompt injection.\n
  • Evidence:\n
  • Ingestion points: Captures and reads stdout/stderr from various project tools (e.g., test runners and linters) into temporary files (SKILL.md Step 2).\n
  • Boundary markers: The preamble explicitly instructs the agent to honor GSTACK_INSTRUCTION blocks only when they appear in the direct tool result of the trusted gstack-skill-start command, creating a strict trust boundary.\n
  • Capability inventory: The skill has permission to execute shell commands, write to project files like CLAUDE.md, and issue AskUserQuestion prompts.\n
  • Sanitization: Employs awk and grep to parse specific error patterns and restricts displayed output to the last 50 lines of the captured logs.\n- [SAFE]: The skill implements security best practices for local file operations and state management.\n
  • Evidence:\n
  • Uses umask 077 and restricted temporary files to secure logs generated during health checks.\n
  • Restricts history persistence to a specific local directory (~/.gstack/projects/$SLUG/).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — health