skills/garrytan/gstack/retro/Gen Agent Trust Hub

retro

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a suite of local helper binaries to manage its workflow and gather metrics.
  • Evidence: Calls to gstack-skill-start, gstack-retro-metrics, gstack-global-discover, gstack-learnings-search, and gstack-question-log located in ~/.claude/skills/gstack/bin/.
  • [COMMAND_EXECUTION]: The skill interacts with external hosting platforms to fetch repository metadata.
  • Evidence: Uses git fetch, gh pr list, and glab mr view to query GitHub and GitLab for merged pull requests and commit history.
  • [DYNAMIC_EXECUTION]: The skill uses dynamic execution patterns to configure its environment and locate components.
  • Evidence: Uses eval to source the output of the local gstack-slug binary into the shell environment.
  • Evidence: Dynamically locates and executes a discovery script using bun run bin/gstack-global-discover.ts if a compiled binary is not present.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from untrusted sources.
  • Ingestion points: Git commit history, CHANGELOG.md, TODOS.md, and various local project metadata files such as ~/.gstack/retro-context.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the processed content.
  • Capability inventory: The skill can execute shell commands via the Bash tool and write JSON snapshots to the project directory.
  • Sanitization: No explicit sanitization of commit messages or markdown content is defined before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:27 PM
Security Audit — agent-trust-hub — retro