plan-eng-review

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill extensively uses the Bash tool to execute a suite of local helper utilities (such as gstack-skill-start, gstack-slug, and gstack-review-log) located within the ~/.claude/skills/gstack/bin/ directory to manage session state, project metadata, and decision logging.
  • [EXTERNAL_DOWNLOADS]: The instructions reference well-known external tools and services like aside.com and OpenAI's codex CLI, recommending their installation through official package managers (e.g., npm install -g @openai/codex).
  • [DATA_EXFILTRATION]: The skill reads project source code and design documents to perform reviews. It sends data to external services via WebSearch and AI-based review agents (Codex and Aside). However, the skill explicitly mandates query sanitization to strip sensitive details like hostnames, IPs, and secrets before any data leaves the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from implementation plans and web research. It implements defensive measures, including clear boundary instructions for sub-agents to treat ingested content as data to be analyzed rather than commands to be executed.
  • [INDIRECT_PROMPT_INJECTION]: (Mandatory Evidence Chain)
  • Ingestion points: Untrusted data is ingested during the 'Scope gate' (user-provided plans) in SKILL.md and via 'Web research' and 'Outside Voice' review results in review-sections.md.
  • Boundary markers: The 'Outside Voice' logic includes explicit safety instructions ('IMPORTANT: Do NOT read or execute any files under ~/.claude/...') to prevent the sub-agent from executing instructions found within the analyzed project files.
  • Capability inventory: The skill utilizes Bash, Write, and WebSearch tools to perform its analysis and research tasks.
  • Sanitization: The skill contains mandatory instructions to sanitize all queries sent to external search engines or AI agents, ensuring sensitive identifiers are removed.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:06 PM
Security Audit — agent-trust-hub — plan-eng-review