investigate
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands to manage session lifecycle, maintain project-specific state in
~/.gstack, and interface with development tools likegit. These operations are transparently defined in the preamble and workflow steps.\n- [DATA_EXFILTRATION]: Usage telemetry is collected to improve the tool, but this is gated by an interactive prompt. Users must explicitly choose to enable telemetry before any data is transmitted to the vendor-controlled service.\n- [SAFE]: No malicious patterns or security risks were identified. The skill incorporates safety mechanisms such as mandatory data sanitization before web searching and scope locking to prevent unintended file modifications during debugging sessions.\n- [EXTERNAL_DOWNLOADS]: The skill handles update checks and artifact synchronization via standard protocols and vendor-owned infrastructure. These processes are documented and do not involve executing untrusted remote code.
Audit Metadata