skills/garrytan/gstack/learn/Gen Agent Trust Hub

learn

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes multiple vendor-provided utilities from the ~/.claude/skills/gstack/bin/ directory, including gstack-skill-start, gstack-slug, gstack-learnings-search, gstack-paths, and gstack-learnings-log. It uses the eval command to integrate the output of gstack-slug and gstack-paths into the execution environment.
  • [DYNAMIC_EXECUTION]: In the implementation of the stats command, the skill uses bun -e to execute a hardcoded JavaScript snippet that processes and aggregates data from the learnings.jsonl file.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the ingestion of historical project data.
  • Ingestion points: Project learning data is read from the learnings.jsonl file via the cat command and the gstack-learnings-search utility.
  • Boundary markers: The skill does not implement explicit delimiters or instructions to ignore potential commands embedded within the retrieved learning insights.
  • Capability inventory: The skill has access to the Bash tool for executing shell commands and the Write and Edit tools for modifying files in the repository.
  • Sanitization: There is no evidence of sanitization or validation performed on the insight field or other data retrieved from the project history before it is processed or presented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — learn