retro
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a suite of local helper binaries to manage its workflow and gather metrics.
- Evidence: Calls to
gstack-skill-start,gstack-retro-metrics,gstack-global-discover,gstack-learnings-search, andgstack-question-loglocated in~/.claude/skills/gstack/bin/. - [COMMAND_EXECUTION]: The skill interacts with external hosting platforms to fetch repository metadata.
- Evidence: Uses
git fetch,gh pr list, andglab mr viewto query GitHub and GitLab for merged pull requests and commit history. - [DYNAMIC_EXECUTION]: The skill uses dynamic execution patterns to configure its environment and locate components.
- Evidence: Uses
evalto source the output of the localgstack-slugbinary into the shell environment. - Evidence: Dynamically locates and executes a discovery script using
bun run bin/gstack-global-discover.tsif a compiled binary is not present. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from untrusted sources.
- Ingestion points: Git commit history,
CHANGELOG.md,TODOS.md, and various local project metadata files such as~/.gstack/retro-context.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the processed content.
- Capability inventory: The skill can execute shell commands via the
Bashtool and write JSON snapshots to the project directory. - Sanitization: No explicit sanitization of commit messages or markdown content is defined before analysis.
Audit Metadata