health
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local binaries for lifecycle management and project-specific development tools to gather metrics.\n
- Evidence:\n
- Execution of vendor binaries:
gstack-skill-start,gstack-slug,gstack-learnings-log, andgstack-skill-end.\n - Execution of project tools:
tsc,biome,eslint,ruff,pytest,cargo test,go test,knip,shellcheck, andgbrain.\n- [INDIRECT_PROMPT_INJECTION]: The skill parses and displays output from external development tools, which represents an attack surface for indirect prompt injection.\n - Evidence:\n
- Ingestion points: Captures and reads stdout/stderr from various project tools (e.g., test runners and linters) into temporary files (SKILL.md Step 2).\n
- Boundary markers: The preamble explicitly instructs the agent to honor
GSTACK_INSTRUCTIONblocks only when they appear in the direct tool result of the trustedgstack-skill-startcommand, creating a strict trust boundary.\n - Capability inventory: The skill has permission to execute shell commands, write to project files like
CLAUDE.md, and issueAskUserQuestionprompts.\n - Sanitization: Employs
awkandgrepto parse specific error patterns and restricts displayed output to the last 50 lines of the captured logs.\n- [SAFE]: The skill implements security best practices for local file operations and state management.\n - Evidence:\n
- Uses
umask 077and restricted temporary files to secure logs generated during health checks.\n - Restricts history persistence to a specific local directory (
~/.gstack/projects/$SLUG/).
Audit Metadata