plan-design-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong directives to override standard agent behavior and tool execution flow. Specifically, the 'Scope gate' is described as a 'hard STOP' that 'overrides everything below' and must be resolved 'before any tool, including preamble and base-branch detection.' It also instructs the agent to follow 'Instruction blocks' (GSTACK_INSTRUCTION_BEGIN) found in tool outputs, which dictates specific runtime behaviors.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources including plan files, DESIGN.md, CLAUDE.md, and TODOS.md. This content is interpolated into prompts for the agent and external subagents (Codex/Claude). While the skill includes a safety check to only honor 'Instruction blocks' from a specific local tool (gstack-skill-start), it lacks broad boundary markers for general plan content. Mandatory Evidence Chain:
  • Ingestion points: Reads plan files (user-provided), DESIGN.md, CLAUDE.md, TODOS.md, and review logs.
  • Boundary markers: Includes a validation rule for GSTACK_INSTRUCTION blocks but lacks delimiters for general file content read via the Read tool.
  • Capability inventory: Executes shell commands via Bash, writes/edits files via Edit, and invokes external model execution via codex exec and AskUserQuestion.
  • Sanitization: Implements a specific provenance check for control instructions, ensuring they only originate from a trusted local tool result.
  • [COMMAND_EXECUTION]: The skill relies extensively on local binaries and scripts located in ~/.claude/skills/gstack/bin/. These include gstack-skill-start, gstack-slug, gstack-paths, gstack-brain-cache, gstack-decision-search, gstack-question-log, and others. These are vendor-provided resources associated with the 'garrytan' author.
  • [DYNAMIC_EXECUTION]: The skill performs dynamic shell environment setup by executing eval on the output of local scripts (gstack-slug and gstack-paths) and source-ing files like gstack-codex-probe. This allows the skill to dynamically alter the agent's shell state based on local system conditions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — plan-design-review