skills/garrytan/gstack/investigate/Gen Agent Trust Hub

investigate

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on several local shell scripts located in $HOME/.claude/skills/gstack/ for operational tasks, including initialization (gstack-skill-start), scope boundary enforcement (check-freeze.sh), and telemetry logging (gstack-skill-end).
  • [DYNAMIC_EXECUTION]: Employs eval to execute output from the gstack-slug utility to dynamically set environment variables and recover project-specific context at the start of a session.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests historical debugging data and project-specific patterns from local JSONL files (learnings.jsonl, eureka.jsonl). While this provides valuable context, it represents a potential surface for indirect prompt injection if malicious data was recorded in previous sessions.
  • [EXTERNAL_DOWNLOADS]: Uses the aside CLI utility and WebSearch tool to perform external research for bug patterns and framework-specific issues. The skill includes explicit instructions to sanitize queries by stripping sensitive information like hostnames and credentials before transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — investigate