plan-eng-review
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively uses the
Bashtool to execute a suite of local helper utilities (such asgstack-skill-start,gstack-slug, andgstack-review-log) located within the~/.claude/skills/gstack/bin/directory to manage session state, project metadata, and decision logging. - [EXTERNAL_DOWNLOADS]: The instructions reference well-known external tools and services like
aside.comand OpenAI'scodexCLI, recommending their installation through official package managers (e.g.,npm install -g @openai/codex). - [DATA_EXFILTRATION]: The skill reads project source code and design documents to perform reviews. It sends data to external services via
WebSearchand AI-based review agents (Codex and Aside). However, the skill explicitly mandates query sanitization to strip sensitive details like hostnames, IPs, and secrets before any data leaves the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from implementation plans and web research. It implements defensive measures, including clear boundary instructions for sub-agents to treat ingested content as data to be analyzed rather than commands to be executed.
- [INDIRECT_PROMPT_INJECTION]: (Mandatory Evidence Chain)
- Ingestion points: Untrusted data is ingested during the 'Scope gate' (user-provided plans) in
SKILL.mdand via 'Web research' and 'Outside Voice' review results inreview-sections.md. - Boundary markers: The 'Outside Voice' logic includes explicit safety instructions ('IMPORTANT: Do NOT read or execute any files under ~/.claude/...') to prevent the sub-agent from executing instructions found within the analyzed project files.
- Capability inventory: The skill utilizes
Bash,Write, andWebSearchtools to perform its analysis and research tasks. - Sanitization: The skill contains mandatory instructions to sanitize all queries sent to external search engines or AI agents, ensuring sensitive identifiers are removed.
Audit Metadata