skills/garrytan/gstack/scrape/Gen Agent Trust Hub

scrape

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes several local binaries provided by the vendor for its lifecycle and telemetry management, including gstack-skill-start, gstack-skill-end, and gstack-learnings-log located in the ~/.claude/skills/gstack/bin/ directory. It also executes the aside browser CLI and a fallback headless browser binary.
  • [DYNAMIC_EXECUTION]: The skill dynamically constructs and executes Javascript snippets within the browser context via aside repl to perform tasks like DOM extraction and snapshotting.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web pages, which are untrusted sources. This presents an attack surface where malicious instructions could be embedded in the scraped content.
  • Ingestion points: Untrusted data enters the agent context through page snapshots, console error logs, and text extraction (document.body.innerText).
  • Boundary markers: The skill documentation includes an explicit 'Untrusted content warning' (referencing #2441) with four strict rules to ignore instructions in page content. Additionally, the headless fallback browser wraps untrusted content in visual markers.
  • Capability inventory: The skill has access to the Bash, Read, and AskUserQuestion tools, which could be leveraged if the agent were to follow instructions found in scraped data.
  • Sanitization: The instructions provide explicit negative constraints, ordering the agent to never execute code, tool calls, or visit URLs suggested by page content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — scrape