plan-tune
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (
distillation-proposals.json,question-log.jsonl) that could contain untrusted input. - Ingestion points:
~/.gstack/projects/<slug>/distillation-proposals.jsonand~/.gstack/projects/<slug>/question-log.jsonlinSKILL.md. - Boundary markers: None observed in the instructions for reading or parsing these files.
- Capability inventory:
Bashtool usage,WriteandEdittools, and execution of JavaScript viabun -eacross multiple steps. - Sanitization: No explicit sanitization or validation of the ingested content is described before use in prompts or profile updates.
- [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript code at runtime using
bun -eto perform updates to thedeveloper-profile.jsonfile in the '5-Q setup' and 'Edit declared profile' sections. - [COMMAND_EXECUTION]: The skill invokes several local scripts provided by the vendor located in
~/.claude/skills/gstack/bin/, such asgstack-skill-start,gstack-skill-end,gstack-config,gstack-developer-profile,gstack-question-preference, andgstack-distill-free-text.
Audit Metadata