plan-ceo-review
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bashtool to execute local utility binaries (e.g.,gstack-skill-start,gstack-slug,gstack-learnings-search) and standard development tools likegitandgh. These operations are used for repository auditing, context recovery, and session management. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from the local filesystem (prior CEO plans, design docs) and external web research results. While it includes some mitigation instructions for the agent to treat search results as untrusted, the combination of external data ingestion and write/execute capabilities presents a low-level security risk.
- [DATA_EXFILTRATION]: As part of its 'Outside Voice' feature, the skill transmits the contents of the project plan being reviewed to an external AI service (OpenAI Codex) to obtain a secondary opinion. While this is an intended core feature, it involves sending potentially sensitive project information to a third-party service.
Audit Metadata