skills/garrytan/gstack/office-hours/Gen Agent Trust Hub

office-hours

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various local binaries and helper scripts (e.g., gstack-skill-start, gstack-slug, gstack-render.ts, gstack-decision-log) located within the ~/.claude/skills/gstack/bin/ directory. These are utilized for lifecycle management, project context recovery, and artifact synchronization within the gstack ecosystem.
  • [EXTERNAL_DOWNLOADS]: Landscape research and web searches are performed through the Aside browser or a WebSearch tool. The skill provides explicit instructions to treat results as untrusted content, cite sources without following instructions, and sanitize queries by stripping sensitive data (IPs, file paths, secrets) before transmission.
  • [DYNAMIC_EXECUTION]: The skill generates HTML wireframe sketches and renders them using a local TypeScript utility (gstack-render.ts) via bun, facilitating visual design exploration within a controlled loopback environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface through the ingestion of external data (web research and second-opinion sub-agents). However, this is mitigated by a mandatory evidence chain: it uses specific boundary markers (treating content as untrusted), maintains a restricted capability inventory (no implementation actions), and employs a sanitization tool (gstack-redact) to scan bytes for sensitive data before writing files to the user's repository.
  • [SAFE]: References to external domains (e.g., ycombinator.com, paulgraham.com, youtube.com) are limited to well-known, trusted educational and application services directly relevant to the skill's stated purpose as a startup brainstorming assistant.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — office-hours