investigate
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on several local shell scripts located in
$HOME/.claude/skills/gstack/for operational tasks, including initialization (gstack-skill-start), scope boundary enforcement (check-freeze.sh), and telemetry logging (gstack-skill-end). - [DYNAMIC_EXECUTION]: Employs
evalto execute output from thegstack-slugutility to dynamically set environment variables and recover project-specific context at the start of a session. - [INDIRECT_PROMPT_INJECTION]: The skill ingests historical debugging data and project-specific patterns from local JSONL files (
learnings.jsonl,eureka.jsonl). While this provides valuable context, it represents a potential surface for indirect prompt injection if malicious data was recorded in previous sessions. - [EXTERNAL_DOWNLOADS]: Uses the
asideCLI utility andWebSearchtool to perform external research for bug patterns and framework-specific issues. The skill includes explicit instructions to sanitize queries by stripping sensitive information like hostnames and credentials before transmission.
Audit Metadata