learn
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes multiple vendor-provided utilities from the
~/.claude/skills/gstack/bin/directory, includinggstack-skill-start,gstack-slug,gstack-learnings-search,gstack-paths, andgstack-learnings-log. It uses theevalcommand to integrate the output ofgstack-slugandgstack-pathsinto the execution environment. - [DYNAMIC_EXECUTION]: In the implementation of the
statscommand, the skill usesbun -eto execute a hardcoded JavaScript snippet that processes and aggregates data from thelearnings.jsonlfile. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of historical project data.
- Ingestion points: Project learning data is read from the
learnings.jsonlfile via thecatcommand and thegstack-learnings-searchutility. - Boundary markers: The skill does not implement explicit delimiters or instructions to ignore potential commands embedded within the retrieved learning insights.
- Capability inventory: The skill has access to the
Bashtool for executing shell commands and theWriteandEdittools for modifying files in the repository. - Sanitization: There is no evidence of sanitization or validation performed on the
insightfield or other data retrieved from the project history before it is processed or presented.
Audit Metadata