plan-design-review
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses strong directives to override standard agent behavior and tool execution flow. Specifically, the 'Scope gate' is described as a 'hard STOP' that 'overrides everything below' and must be resolved 'before any tool, including preamble and base-branch detection.' It also instructs the agent to follow 'Instruction blocks' (GSTACK_INSTRUCTION_BEGIN) found in tool outputs, which dictates specific runtime behaviors.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources including plan files,
DESIGN.md,CLAUDE.md, andTODOS.md. This content is interpolated into prompts for the agent and external subagents (Codex/Claude). While the skill includes a safety check to only honor 'Instruction blocks' from a specific local tool (gstack-skill-start), it lacks broad boundary markers for general plan content. Mandatory Evidence Chain: - Ingestion points: Reads plan files (user-provided),
DESIGN.md,CLAUDE.md,TODOS.md, and review logs. - Boundary markers: Includes a validation rule for
GSTACK_INSTRUCTIONblocks but lacks delimiters for general file content read via theReadtool. - Capability inventory: Executes shell commands via
Bash, writes/edits files viaEdit, and invokes external model execution viacodex execandAskUserQuestion. - Sanitization: Implements a specific provenance check for control instructions, ensuring they only originate from a trusted local tool result.
- [COMMAND_EXECUTION]: The skill relies extensively on local binaries and scripts located in
~/.claude/skills/gstack/bin/. These includegstack-skill-start,gstack-slug,gstack-paths,gstack-brain-cache,gstack-decision-search,gstack-question-log, and others. These are vendor-provided resources associated with the 'garrytan' author. - [DYNAMIC_EXECUTION]: The skill performs dynamic shell environment setup by executing
evalon the output of local scripts (gstack-slugandgstack-paths) andsource-ing files likegstack-codex-probe. This allows the skill to dynamically alter the agent's shell state based on local system conditions.
Audit Metadata