skills/garrytan/gstack/landing-report/Gen Agent Trust Hub

landing-report

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes several local binaries located within the user's home directory (e.g., ~/.claude/skills/gstack/bin/gstack-skill-start, gstack-next-version, gstack-skill-end). These are vendor-provided utilities used for lifecycle management, versioning logic, and telemetry.
  • [COMMAND_EXECUTION]: Uses standard development tools including git and gh (GitHub CLI) to query repository state and pull request metadata.
  • [DYNAMIC_EXECUTION]: Employs eval on the output of the local gstack-slug utility to source environment variables into the current shell session. This is a standard mechanism for CLI-based environment configuration.
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to respond to instruction blocks (onboarding/consent) generated by the gstack-skill-start tool. Security is maintained by requiring a matching SESSION_ID from the tool's immediate output, preventing the agent from following instructions embedded in untrusted external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:57 AM
Security Audit — agent-trust-hub — landing-report