skills/garrytan/gstack/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several local command-line tools (e.g., gstack-skill-start, gstack-paths, gstack-review-log, gstack-learnings-search) located in the vendor-owned ~/.claude/skills/gstack/bin/ directory to manage project context and log review activities.
  • [EXTERNAL_DOWNLOADS]: It interacts with external services, specifically aside.com for research and openai.com (Codex) for structural and adversarial code reviews, following neutral discovery and reporting patterns for these well-known services.
  • [DYNAMIC_EXECUTION]: The skill uses the bun runtime to execute JavaScript code snippets dynamically to perform internal operations like computing shared-code fingerprints.
  • [DATA_EXFILTRATION]: It logs operational telemetry, including session identifiers and task outcomes, via local binaries (gstack-question-log, gstack-skill-end) for analytics and learning purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from potentially untrusted sources such as PR bodies, commit logs, and Greptile comments. It manages these risks by applying a trust-envelope pattern via the gstack-issue-guard utility to prevent external content from influencing the agent's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 11:06 PM
Security Audit — agent-trust-hub — review