review
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several local command-line tools (e.g.,
gstack-skill-start,gstack-paths,gstack-review-log,gstack-learnings-search) located in the vendor-owned~/.claude/skills/gstack/bin/directory to manage project context and log review activities. - [EXTERNAL_DOWNLOADS]: It interacts with external services, specifically
aside.comfor research andopenai.com(Codex) for structural and adversarial code reviews, following neutral discovery and reporting patterns for these well-known services. - [DYNAMIC_EXECUTION]: The skill uses the
bunruntime to execute JavaScript code snippets dynamically to perform internal operations like computing shared-code fingerprints. - [DATA_EXFILTRATION]: It logs operational telemetry, including session identifiers and task outcomes, via local binaries (
gstack-question-log,gstack-skill-end) for analytics and learning purposes. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from potentially untrusted sources such as PR bodies, commit logs, and Greptile comments. It manages these risks by applying a trust-envelope pattern via the
gstack-issue-guardutility to prevent external content from influencing the agent's instructions.
Audit Metadata