skills/garrytan/gstack/plan-tune/Gen Agent Trust Hub

plan-tune

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external files (distillation-proposals.json, question-log.jsonl) that could contain untrusted input.
  • Ingestion points: ~/.gstack/projects/<slug>/distillation-proposals.json and ~/.gstack/projects/<slug>/question-log.jsonl in SKILL.md.
  • Boundary markers: None observed in the instructions for reading or parsing these files.
  • Capability inventory: Bash tool usage, Write and Edit tools, and execution of JavaScript via bun -e across multiple steps.
  • Sanitization: No explicit sanitization or validation of the ingested content is described before use in prompts or profile updates.
  • [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript code at runtime using bun -e to perform updates to the developer-profile.json file in the '5-Q setup' and 'Edit declared profile' sections.
  • [COMMAND_EXECUTION]: The skill invokes several local scripts provided by the vendor located in ~/.claude/skills/gstack/bin/, such as gstack-skill-start, gstack-skill-end, gstack-config, gstack-developer-profile, gstack-question-preference, and gstack-distill-free-text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — plan-tune