plan-devex-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several utility scripts located in the vendor-owned directory ~/.claude/skills/gstack/bin/ (e.g., gstack-skill-start, gstack-skill-end, gstack-slug, and gstack-question-log). These tools are used for session initialization, telemetry, logging decision history, and environment configuration.
  • [REMOTE_CODE_EXECUTION]: The skill invokes external CLI tools such as codex (by OpenAI) and aside to provide independent plan challenges and web research capabilities. It also provides instructions for installing @openai/codex if it is not already present on the system.
  • [EXTERNAL_DOWNLOADS]: Fetches data from the web using aside.com or a WebSearch tool for competitive benchmarking. The instructions include a mandatory sanitization step to strip hostnames, IPs, file paths, and secrets from queries before they are sent, and require treating all returned content as untrusted.
  • [INDIRECT_PROMPT_INJECTION]: As a code and plan review tool, the skill ingests untrusted data from the repository (e.g., git diff, README.md, package.json) and the web. To mitigate risks, the instructions explicitly command the agent to treat external content as read-only, to cite sources without following instructions found within them, and to use boundary markers during processing.
  • [DYNAMIC_EXECUTION]: Uses eval to execute the output of gstack-slug to set environment variables for the session. This is a standard pattern within the gstack toolset for managing project-specific context.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — plan-devex-review