skills/garrytan/gstack/qa-only/Gen Agent Trust Hub

qa-only

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs the eval command to execute shell output generated by the local gstack-slug utility during context recovery.
  • [COMMAND_EXECUTION]: The skill executes multiple local binaries from the vendor infrastructure (e.g., gstack-skill-start, gstack-skill-end, and gstack-learnings-log) to manage session lifecycle, telemetry, and operational insights.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external web pages via browser automation tools. It includes specific defensive instructions requiring the agent to treat all page content as untrusted data rather than instructions.
  • [PROMPT_INJECTION]: The skill supports dynamic instruction blocks that can be injected from tool output during the preamble, which are used to adjust agent behavior for specific session requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — qa-only